Key transmission method, device, terminal and network-side device for a temporary group

The network-side device and key management server jointly generate temporary group identifiers and keys, which solves the problem of temporary group call in the prior art that cannot be compatible with Ad-hoc mode and predefined dynamic reorganization mode, and realizes the widespread application and flexible application of security information.

CN115334504BActive Publication Date: 2025-07-11DATANG MOBILE COMM EQUIP CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202110507622.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-05-10
Publication Date
2025-07-11
Estimated Expiration
2041-05-10

AI Technical Summary

Technical Problem

The prior art is not compatible with temporary group calls based on predefined dynamic reorganization and temporary group calls in Ad-hoc mode, and the key transmission method cannot be applied to all temporary group calls scenarios.

Method used

The temporary group identifier and random number are generated by the network side device, and the temporary group key is generated in combination with the key management server, so as to realize the transmission of temporary group member identification information and the determination of session keys. It is suitable for temporary group calls in Ad-hoc mode and predefined dynamic reorganization mode.

Benefits of technology

It realizes the generation and issuance of security information during temporary group calls, which is suitable for a variety of temporary group call models, expands application scenarios, conforms to the definition of entity roles by the existing architecture, and improves security and flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115334504B_ABST
    Figure CN115334504B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a method, apparatus, terminal, and network-side device for key transmission of a temporary group. The method includes: when a first request sent by a first terminal meets a first preset condition, sending a reorganization request to a group management server (GMS); where the reorganization request carries temporary group member identification information corresponding to the first request; receiving a first response message sent by the GMS according to the reorganization request; where the first response message carries a temporary group identifier; generating a random number corresponding to the temporary group identifier, and the random number is used for the first terminal and a second terminal to determine a session key corresponding to the first request; where the second terminal is the terminal corresponding to the temporary group member identification information. The above solution solves the problem that the prior art can only provide key distribution for the temporary group formation process based on predefined dynamic reorganization, and is not applicable to the temporary group call process in the Ad-hoc mode, and has a wider application range.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a method, device, terminal, and network-side device for key transmission of a temporary group. Background Art

[0002] MC (Mission Critical) group services use a group master key (GMK) to protect the security of each group service content, and each GMK is shared by the group members. After a group is created in a GMS (Group Management Server), the GMS needs to distribute the GMK of the group to the MC Service Clients (Mission Critical Service Clients) of the corresponding group members, where the MC Service Client is on the MC Service UE (Mission Critical Service User Equipment). After creating a group, the GMS masters the relationship between a group and the user of its group members, and the group member users are identified by the MC Service ID.

[0003] The GMS requests the GMK and the corresponding GMK ID for a group from the KMS (Key Management Server). The KMS is responsible for generating and configuring keys and related information and sending them to the GMS. The GMS encrypts the GMK and is responsible for distributing it to the group members.

[0004] However, the existing technology can only provide key distribution for the temporary group formation process based on predefined dynamic recombination, and is not applicable to the temporary group call process in the Ad-hoc mode. Summary of the Invention

[0005] The purpose of the present invention is to provide a method, device, terminal, and network-side device for key transmission of a temporary group to solve the problem that the existing key transmission method cannot be compatible with the temporary group call based on predefined dynamic recombination and the temporary group call in the Ad-hoc mode.

[0006] To achieve the above purpose, the present invention provides a method for key transmission of a temporary group, which is executed by a network-side device and includes:

[0007] When a first request sent by a first terminal meets a first preset condition, sending a recombination request to a group management server GMS; wherein, the recombination request carries the temporary group member identification information corresponding to the first request.

[0008] Receive the first response information sent by the GMS according to the reorganization request; wherein, the first response information carries a temporary group identifier;

[0009] Generate a random number corresponding to the temporary group identifier, and the random number is used for the first terminal and the second terminal to determine the session key corresponding to the first request; wherein, the second terminal is the terminal corresponding to the temporary group member identifier information.

[0010] Wherein, before sending the reorganization request to the group management server GMS, the method further includes:

[0011] Send a key material request to the key management server KMS;

[0012] Receive the second response information sent by the KMS according to the key material request; wherein, the second response information includes a temporary group key and a temporary group key identifier.

[0013] Wherein, the first request carries the temporary group member identifier information.

[0014] Wherein, the first preset condition is one of the following:

[0015] The first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call;

[0016] The first request is a predefined dynamic reorganization request.

[0017] Wherein, in the case that the first request is a first group call request, after the method generates a random number corresponding to the temporary group identifier, the method further includes:

[0018] Send a second group call request to the second terminal; wherein, the second group call request carries the random number, the temporary group identifier, and the call type corresponding to the first group call request;

[0019] Receive the third response information sent by the second terminal according to the second group call request; wherein, the third response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request;

[0020] Send a fourth response information to the first terminal; wherein, the fourth response information is used to indicate that the temporary group call corresponding to the first request is successfully established; the fourth response information carries a temporary group identifier and a random number.

[0021] Wherein, when the first request is a predefined dynamic reorganization request, after generating a random number corresponding to the temporary group identifier, the method further includes:

[0022] Sending the predefined dynamic reorganization request to the second terminal;

[0023] Receiving fifth response information sent by the second terminal according to the predefined dynamic reorganization request;

[0024] Establishing a group association relationship between the second terminal and the temporary group identifier;

[0025] Sending sixth response information to the first terminal; wherein, the sixth response information carries the temporary group identifier and the random number.

[0026] Wherein, the method further includes:

[0027] Receiving a third group call request sent by the first terminal; wherein, the third group call request carries the temporary group identifier;

[0028] Sending a fourth group call request to the second terminal associated with the temporary group identifier; wherein, the fourth group call request carries the random number and the temporary group identifier;

[0029] Receiving seventh response information sent by the second terminal according to the predefined dynamic reorganization request; wherein, the seventh response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request;

[0030] Sending eighth response information to the first terminal; wherein, the eighth response information carries the temporary group identifier, and the eighth response information is used to indicate that the temporary group call is successfully established.

[0031] Wherein, the method further includes:

[0032] When communicating with the GMS, encrypting the temporary group key and the temporary group key identifier using a preset key.

[0033] An embodiment of the present invention further provides a method for transmitting a key of a temporary group, which is executed by a first terminal and includes:

[0034] Sending a first request to a network-side device; wherein, the first request carries temporary group member identification information;

[0035] Receive a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to a reorganization request sent by a network-side device, the reorganization request is sent by the network-side device when the first request meets a first preset condition, and the reorganization request carries temporary group member identifier information, a temporary group key, and a temporary group key identifier corresponding to the first request;

[0036] Obtain a random number; wherein, the random number corresponds to the temporary group identifier in the first response information sent by the GMS, and the first response information is sent by the GMS according to the reorganization request sent by the network-side device;

[0037] Determine a session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

[0038] Wherein, the first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call; or,

[0039] The first request is a predefined dynamic reorganization request.

[0040] Wherein, when the first request is a first group call request, the obtaining of the random number includes:

[0041] Receive a fourth response information sent by the network-side device; wherein, the fourth response information is used to indicate that the temporary group call corresponding to the first request is successfully established; the fourth response information carries a temporary group identifier and a random number.

[0042] Wherein, when the first request is a predefined dynamic reorganization request, the obtaining of the random number includes:

[0043] Receive a sixth response information sent by the network-side device; wherein, the sixth response information carries a temporary group identifier and a random number.

[0044] Wherein, after receiving the sixth response information sent by the network-side device, the method further includes:

[0045] Send a third group call request to the network-side device; wherein, the third group call request carries the temporary group identifier;

[0046] Receive an eighth response information sent by the network-side device; wherein, the eighth response information carries a temporary group identifier, and the eighth response information is used to indicate that the temporary group call is successfully established.

[0047] Wherein, after receiving the group configuration request sent by the GMS, the method further includes:

[0048] Sending a tenth response message to the GMS according to the group configuration request; wherein, the tenth response message is used to indicate that the first terminal has accepted the group configuration request.

[0049] An embodiment of the present invention further provides a key transmission method for a temporary group, which is executed by a second terminal and includes:

[0050] Receiving a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to a reorganization request sent by a network-side device, the reorganization request is sent by the network-side device when a first request meets a first preset condition, and the reorganization request carries temporary group member identifier information, a temporary group key, and a temporary group key identifier corresponding to the first request;

[0051] Obtaining a random number; wherein, the random number corresponds to the temporary group identifier in the first response message sent by the GMS, and the first response message is sent by the GMS according to the reorganization request sent by the network-side device;

[0052] Determining a session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

[0053] Wherein, after receiving the group configuration request sent by the GMS, the method further includes:

[0054] Sending a ninth response message to the GMS according to the group configuration request; wherein, the ninth response message is used to indicate that the second terminal has accepted the group configuration request.

[0055] Wherein, the obtaining of the random number includes:

[0056] Receiving a second group call request sent by a network-side device; wherein, the second group call request carries a random number, the temporary group identifier, and a call type.

[0057] Wherein, the method further includes:

[0058] Sending a third response message to the network-side device; wherein, the third response message is used to indicate that the second terminal has joined the temporary group call corresponding to the first request.

[0059] Wherein, the method further includes:

[0060] Receiving a predefined dynamic reorganization request sent by a network-side device;

[0061] Send fifth response information to the network side device according to the predefined dynamic reorganization request.

[0062] Among them, obtaining the random number includes:

[0063] Receive the fourth group call request sent by the network side device; among them, the fourth group call request carries a random number and the temporary group identifier.

[0064] Among them, the method further includes:

[0065] Send seventh response information to the network side device according to the fourth group call request; among them, the seventh response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request.

[0066] An embodiment of the present invention further provides a method for transmitting a key of a temporary group, which is executed by a GMS and includes:

[0067] Receive a reorganization request sent by the network side device; among them, the reorganization request carries temporary group member identification information, a temporary group key, and a temporary group key identifier;

[0068] Send a group configuration request to the first terminal and the second terminal corresponding to the temporary group member identification information according to the reorganization request; among them, the group configuration request carries a temporary group identifier, the temporary group key, and the temporary group key identifier;

[0069] Receive the ninth response information sent by the second terminal according to the group configuration request, and receive the tenth response information sent by the first terminal according to the group configuration request;

[0070] Send first response information to the network side device; among them, the first response information carries a temporary group identifier.

[0071] Among them, the method further includes:

[0072] When communicating with the network side device, encrypt the temporary group key and the temporary group key identifier by using a preset key.

[0073] An embodiment of the present invention further provides a method for transmitting a key of a temporary group, which is executed by a KMS and includes:

[0074] Receive a key material request sent by the network side device;

[0075] Send second response information to the network side device; among them, the second response information includes a temporary group key and its corresponding temporary group key identifier.

[0076] An embodiment of the present invention further provides a network-side device, including a memory, a transceiver, and a processor:

[0077] The memory is used to store a computer program; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer program in the memory and perform the following operations:

[0078] When a first request sent by a first terminal meets a first preset condition, send a reorganization request to a group management server GMS; wherein, the reorganization request carries temporary group member identification information corresponding to the first request;

[0079] Receive a first response message sent by the GMS according to the reorganization request; wherein, the first response message carries a temporary group identifier;

[0080] Generate a random number corresponding to the temporary group identifier, and the random number is used for the first terminal and a second terminal to determine a session key corresponding to the first request; wherein, the second terminal is the terminal corresponding to the temporary group member identification information.

[0081] Wherein, before sending the reorganization request to the group management server GMS, the method further includes:

[0082] Send a key material request to a key management server KMS;

[0083] Receive a second response message sent by the KMS according to the key material request; wherein, the second response message includes a temporary group key and a temporary group key identifier.

[0084] Wherein, the first request carries the temporary group member identification information.

[0085] Wherein, the first preset condition is one of the following:

[0086] The first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call;

[0087] The first request is a predefined dynamic reorganization request.

[0088] Wherein, when the first request is a first group call request, after generating the random number corresponding to the temporary group identifier, the processor is further used to read the computer program in the memory and perform the following operations:

[0089] Send a second group call request to the second terminal; wherein, the second group call request carries the random number, the temporary group identifier, and the call type corresponding to the first group call request;

[0090] Receive third response information sent by the second terminal according to the second group call request; wherein, the third response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request;

[0091] Send fourth response information to the first terminal; wherein, the fourth response information is used to indicate that the temporary group call corresponding to the first request is successfully established; the fourth response information carries a temporary group identifier and a random number.

[0092] Wherein, when the first request is a predefined dynamic reorganization request, after generating a random number corresponding to the temporary group identifier, the processor is further configured to read a computer program in the memory and perform the following operations:

[0093] Send the predefined dynamic reorganization request to the second terminal;

[0094] Receive fifth response information sent by the second terminal according to the predefined dynamic reorganization request;

[0095] Establish a group association relationship between the second terminal and the temporary group identifier;

[0096] Send sixth response information to the first terminal; wherein, the sixth response information carries a temporary group identifier and a random number.

[0097] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0098] Receive a third group call request sent by the first terminal; wherein, the third group call request carries the temporary group identifier;

[0099] Send a fourth group call request to the second terminal associated with the temporary group identifier; wherein, the fourth group call request carries the random number and the temporary group identifier;

[0100] Receive seventh response information sent by the second terminal according to the predefined dynamic reorganization request; wherein, the seventh response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request;

[0101] Send eighth response information to the first terminal; wherein, the eighth response information carries a temporary group identifier, and the eighth response information is used to indicate that the temporary group call is successfully established.

[0102] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0103] When communicating with the GMS, encrypt the temporary group key and the temporary group key identifier using a preset key.

[0104] An embodiment of the present invention further provides a key transmission device for a temporary group, which is applied to a network-side device and includes:

[0105] A first request unit, configured to send a reorganization request to a group management server GMS when a first request sent by a first terminal meets a first preset condition; wherein, the reorganization request carries temporary group member identification information corresponding to the first request;

[0106] A first receiving unit, configured to receive first response information sent by the GMS according to the reorganization request; wherein, the first response information carries a temporary group identifier;

[0107] Generate a random number corresponding to the temporary group identifier, where the random number is used by the first terminal and a second terminal to determine a session key corresponding to the first request; wherein, the second terminal is the terminal corresponding to the temporary group member identification information.

[0108] An embodiment of the present invention further provides a terminal, where the terminal is a first terminal and includes a memory, a transceiver, and a processor:

[0109] The memory is used to store a computer program; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer program in the memory and perform the following operations:

[0110] Send a first request to a network-side device; wherein, the first request carries temporary group member identification information;

[0111] Receive a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to a reorganization request sent by the network-side device, the reorganization request is sent by the network-side device when the first request meets a first preset condition, and the reorganization request carries the temporary group member identification information, the temporary group key, and the temporary group key identifier corresponding to the first request;

[0112] Obtain a random number; wherein, the random number corresponds to the temporary group identifier in the first response information sent by the GMS, and the first response information is sent by the GMS according to the reorganization request sent by the network-side device;

[0113] Determine a session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

[0114] Wherein, the first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call; or,

[0115] The first request is a predefined dynamic reorganization request.

[0116] Wherein, when the first request is a first group call request, the processor is further configured to read a computer program in the memory and perform the following operations:

[0117] Receive fourth response information sent by the network side device; wherein, the fourth response information is used to indicate that the temporary group call corresponding to the first request is successfully established; the fourth response information carries a temporary group identifier and a random number.

[0118] Wherein, when the first request is a predefined dynamic reorganization request, the processor is further configured to read a computer program in the memory and perform the following operations:

[0119] Receive sixth response information sent by the network side device; wherein, the sixth response information carries a temporary group identifier and a random number.

[0120] Wherein, after receiving the sixth response information sent by the network side device, the processor is further configured to read a computer program in the memory and perform the following operations:

[0121] Send a third group call request to the network side device; wherein, the third group call request carries the temporary group identifier;

[0122] Receive eighth response information sent by the network side device; wherein, the eighth response information carries a temporary group identifier, and the eighth response information is used to indicate that the temporary group call is successfully established.

[0123] Wherein, after receiving the group configuration request sent by the GMS, the processor is further configured to read a computer program in the memory and perform the following operations:

[0124] According to the group configuration request, send a tenth response information to the GMS; wherein, the tenth response information is used to indicate that the first terminal has accepted the group configuration request.

[0125] An embodiment of the present invention further provides a key transmission device for a temporary group, which is applied to a first terminal and includes:

[0126] A first call unit, configured to send a first request to a network side device; wherein, the first request carries temporary group member identification information;

[0127] A first recombination unit for receiving a group configuration request sent by a GMS; wherein the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to a recombination request sent by a network-side device, the recombination request is sent by the network-side device when a first request meets a first preset condition, and the recombination request carries temporary group member identifier information, a temporary group key, and a temporary group key identifier corresponding to the first request;

[0128] Obtain a random number; wherein the random number corresponds to the temporary group identifier in the first response information sent by the GMS, and the first response information is sent by the GMS according to the recombination request sent by the network-side device;

[0129] Determine a session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

[0130] An embodiment of the present invention further provides a terminal, which is a second terminal and includes a memory, a transceiver, and a processor:

[0131] The memory is used for storing a computer program; the transceiver is used for transceiving data under the control of the processor; the processor is used for reading the computer program in the memory and performing the following operations:

[0132] Receive a group configuration request sent by a GMS; wherein the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to a recombination request sent by a network-side device, the recombination request is sent by the network-side device when a first request meets a first preset condition, and the recombination request carries temporary group member identifier information, a temporary group key, and a temporary group key identifier corresponding to the first request;

[0133] Obtain a random number; wherein the random number corresponds to the temporary group identifier in the first response information sent by the GMS, and the first response information is sent by the GMS according to the recombination request sent by the network-side device;

[0134] Determine a session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

[0135] Wherein, after receiving the group configuration request sent by the GMS, the processor is further used for reading the computer program in the memory and performing the following operations:

[0136] Send a ninth response message to the GMS according to the group configuration request; wherein, the ninth response message is used to indicate that the second terminal has accepted the group configuration request.

[0137] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0138] Receive a second group call request sent by a network-side device; wherein, the second group call request carries a random number, the temporary group identifier, and a call type.

[0139] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0140] Send a third response message to the network-side device; wherein, the third response message is used to indicate that the second terminal has joined the temporary group call corresponding to the first request.

[0141] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0142] Receive a predefined dynamic reorganization request sent by a network-side device;

[0143] Send a fifth response message to the network-side device according to the predefined dynamic reorganization request.

[0144] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0145] Receive a fourth group call request sent by a network-side device; wherein, the fourth group call request carries a random number and the temporary group identifier.

[0146] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0147] Send a seventh response message to the network-side device according to the fourth group call request; wherein, the seventh response message is used to indicate that the second terminal has joined the temporary group call corresponding to the first request.

[0148] An embodiment of the present invention further provides a key transmission device for a temporary group, which is applied to a second terminal and includes:

[0149] A second receiving unit, configured to receive a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to a reorganization request sent by a network-side device, the reorganization request is sent by the network-side device when a first request meets a first preset condition, and the reorganization request carries temporary group member identifier information, a temporary group key, and a temporary group key identifier corresponding to the first request;

[0150] A second obtaining unit, configured to obtain a random number; wherein, the random number corresponds to the temporary group identifier in the first response information sent by the GMS, and the first response information is sent by the GMS according to the reorganization request sent by the network-side device;

[0151] A second determining unit, configured to determine a session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

[0152] An embodiment of the present invention further provides a GMS, including a memory, a transceiver, and a processor:

[0153] The memory is configured to store a computer program; the transceiver is configured to send and receive data under the control of the processor; the processor is configured to read the computer program in the memory and perform the following operations:

[0154] Receive a reorganization request sent by a network-side device; wherein, the reorganization request carries temporary group member identifier information, a temporary group key, and a temporary group key identifier;

[0155] According to the reorganization request, send a group configuration request to a first terminal and a second terminal corresponding to the temporary group member identifier information; wherein, the group configuration request carries a temporary group identifier, the temporary group key, and the temporary group key identifier;

[0156] Receive a ninth response information sent by the second terminal according to the group configuration request, and receive a tenth response information sent by the first terminal according to the group configuration request;

[0157] Send a first response information to the network-side device; wherein, the first response information carries a temporary group identifier.

[0158] Wherein, the processor is further configured to read the computer program in the memory and perform the following operations:

[0159] When communicating with the network-side device, encrypt the temporary group key and the temporary group key identifier by using a preset key.

[0160] An embodiment of the present invention further provides a key transmission device for a temporary group, which is applied to GMS and includes:

[0161] A fourth receiving unit, configured to receive a reorganization request sent by a network-side device; wherein, the reorganization request carries temporary group member identification information, a temporary group key, and a temporary group key identifier;

[0162] A second sending unit, configured to send a group configuration request to a first terminal and a second terminal corresponding to the temporary group member identification information according to the reorganization request; wherein, the group configuration request carries a temporary group identifier, the temporary group key, and the temporary group key identifier;

[0163] A fifth receiving unit, configured to receive a ninth response message sent by the second terminal according to the group configuration request, and receive a tenth response message sent by the first terminal according to the group configuration request;

[0164] A first response unit, configured to send a first response message to the network-side device; wherein, the first response message carries a temporary group identifier.

[0165] An embodiment of the present invention further provides a KMS, including a memory, a transceiver, and a processor:

[0166] The memory is configured to store a computer program; the transceiver is configured to send and receive data under the control of the processor; the processor is configured to read the computer program in the memory and perform the following operations:

[0167] Receive a key material request sent by a network-side device;

[0168] Send a second response message to the network-side device; wherein, the second response message includes a temporary group key and its corresponding temporary group key identifier.

[0169] An embodiment of the present invention further provides a key transmission device for a temporary group, which is applied to KMS and includes:

[0170] A third receiving unit, configured to receive a key material request sent by a network-side device;

[0171] A second response unit, configured to send a second response message to the network-side device; wherein, the second response message includes a temporary group key and its corresponding temporary group key identifier.

[0172] An embodiment of the present invention further provides a processor-readable storage medium, which stores a computer program, and the computer program is used to cause the processor to perform the method as described above.

[0173] The above technical solution of the present invention has at least the following beneficial effects:

[0174] In the above technical solution of the embodiment of the present invention, the security information related to the ad hoc group service (random number, ad hoc group key, and ad hoc group key identifier) is generated by the service control server, and then the security information related to the ad hoc group service can be sent to the terminal during the subsequent group call process, without the need to concern whether the group call object has belonged to a group. Therefore, it can be compatible with the ad hoc group call based on predefined dynamic recombination and the ad hoc mode ad hoc group call, and has a wider application range. BRIEF DESCRIPTION OF THE DRAWINGS

[0175] Figure 1 It is a schematic diagram of the wireless communication system architecture according to the embodiment of the present application;

[0176] Figure 2 It shows a schematic diagram of the 3GPP MC system architecture in the prior art;

[0177] Figure 3 It shows a schematic flow chart of the key transmission method according to the embodiment of the present invention Figure 1 ;

[0178] Figure 4 It shows a schematic flow chart of the key transmission method according to the embodiment of the present invention for the ad hoc group call in the ad hoc mode;

[0179] Figure 5 It shows one of the schematic flow charts of the key transmission method for predefined dynamic recombination according to the embodiment of the present invention;

[0180] Figure 6 It shows another schematic flow chart of the key transmission method for predefined dynamic recombination according to the embodiment of the present invention;

[0181] Figure 7 It shows a schematic flow chart of the key transmission method according to the embodiment of the present invention Figure 2 ;

[0182] Figure 8 It shows a schematic flow chart of the key transmission method according to the embodiment of the present invention Figure 3 ;

[0183] Figure 9 It shows a schematic flow chart of the key transmission method according to the embodiment of the present invention Figure 4 ;

[0184] Figure 10 It shows a schematic flow chart of the key transmission method according to the embodiment of the present invention Figure 5 ;

[0185] Figure 11 It shows a schematic diagram of the network side device structure according to the embodiment of the present invention;

[0186] Figure 12 It shows a schematic diagram of the terminal structure according to the embodiment of the present invention;

[0187] Figure 13 Schematic diagram of the key transmission device for the temporary group in the embodiment of the present invention Figure 1 ;

[0188] Figure 14 Schematic diagram of the key transmission device for the temporary group in the embodiment of the present invention Figure 2 ;

[0189] Figure 15 Schematic diagram of the key transmission device for the temporary group in the embodiment of the present invention Figure 3 ;

[0190] Figure 16 Schematic diagram of the key transmission device for the temporary group in the embodiment of the present invention Figure 4 ;

[0191] Figure 17 Schematic diagram of the key transmission device for the temporary group in the embodiment of the present invention Figure 5 . Detailed implementation manners

[0192] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0193] In the embodiments of the present application, the term "and / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0194] In the embodiments of the present application, the term "a plurality of" refers to two or more, and other quantifiers are similar thereto.

[0195] It should be noted that the technical solutions provided in the embodiments of this application can be applied to multiple systems, especially 5G systems. For example, the applicable systems can be the global system of mobile communication (GMS) system, code division multiple access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) general packet radio service (GPRS) system, long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, long term evolution advanced (LTE-A) system, universal mobile telecommunication system (UMTS), worldwide interoperability for microwave access (WiMAX) system, 5G New Radio (NR) system, etc. Both terminals and network devices are included in these multiple systems. The system may also include a core network part, such as the Evolved Packet System (EPS), 5G System (5GS), etc.

[0196] Figure 1 The block diagram of a wireless communication system to which the embodiments of this application can be applied is shown. The wireless communication system includes a terminal and a network device.

[0197] The terminal involved in the embodiments of the present application can be a device that provides voice and / or data connectivity to users, such as a handheld device with wireless connection capabilities, or other processing devices connected to a wireless modem, etc. In different systems, the name of the terminal may also be different. For example, in a 5G system, the terminal can be called a User Equipment (UE). The wireless terminal can communicate with one or more core networks (CN) via a Radio Access Network (RAN). The wireless terminal can be a mobile terminal, such as a mobile phone (or a "cellular" phone) and a computer with a mobile terminal. For example, it can be a portable, pocket-sized, handheld, computer-integrated, or vehicle-mounted mobile device that exchanges language and / or data with the wireless access network. For example, devices such as Personal Communication Service (PCS) phones, cordless phones, Session Initiated Protocol (SIP) phones, Wireless Local Loop (WLL) stations, and Personal Digital Assistant (PDA). The wireless terminal can also be called a system, a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, an access point, a remote terminal device, an access terminal device, a user terminal device, a user agent, a user device, which is not limited in the embodiments of the present application.

[0198] The network device involved in the embodiments of this application can be a base station, which may include multiple cells that provide services to terminals. Depending on specific application scenarios, the base station can also be referred to as an access point, or it can be a device in the access network that communicates with wireless terminals through one or more sectors over the air interface, or other names. The network device can be used to mutually replace the received air frames and Internet Protocol (IP) packets, acting as a router between the wireless terminal and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The network device can also coordinate the attribute management of the air interface. For example, the network device involved in the embodiments of this application can be a network device (Base Transceiver Station, BTS) in a Global System for Mobile communications (GSM) or Code Division Multiple Access (CDMA), or it can be a network device (NodeB) in Wide-band Code Division Multiple Access (WCDMA), or it can also be an evolved network device (evolutional Node B, eNB or e-NodeB) in a Long Term Evolution (LTE) system, a 5G base station (gNB) in a 5G network architecture (next generation system), or it can be a Home evolved Node B (HeNB), a relay node, a femto, a pico, etc. The embodiments of this application do not limit this. In some network architectures, the network device can include a centralized unit (centralized unit, CU) node and a distributed unit (distributed unit, DU) node, and the centralized unit and the distributed unit can also be arranged separately geographically.

[0199] The network device and the terminal can each use one or more antennas for Multi-Input Multi-Output (MIMO) transmission. The MIMO transmission can be Single User MIMO (SU-MIMO) or Multiple User MIMO (MU-MIMO). Depending on the form and quantity of the combined root antennas, the MIMO transmission can be 2D-MIMO, 3D-MIMO, FD-MIMO or massive-MIMO, or it can also be diversity transmission, precoding transmission, beamforming transmission, etc.

[0200] First, the content involved in the solution provided by the embodiments of the present application will be introduced below.

[0201] Regarding the architecture and existing security solutions of 3GPP (3rd Generation Partnership Project) MCPTT:

[0202] As Figure 2 shown, it is the architecture of the 3GPP MC Service system. Among them, the MC Service Server (Mission Critical Service Server) is responsible for MC service control, including call establishment, associating the called user with the group, and querying group members from the GMS (Group Management Server). The corresponding client of the MCService Server is the MC Service Client (the MCPTT Server, MCVideo Server, and MCData Server respectively correspond to the MCPTT Client, MCVideo Client, and MCData Client), and the client and the Server communicate through the MCPTT-1, MCVideo-1, and MCData-cap-1 interfaces respectively.

[0203] The GMS is responsible for group establishment, deletion, management and update of group members (i.e., addition, deletion, and modification), distribution of group configuration information to group members, distribution of group keys (GMK) to group members, and allocation and maintenance of group identifiers (i.e., group IDs). The corresponding client of the GMS is the Group Management Client (GMC), which communicates with the GMS through the CSC-2 interface.

[0204] The KMS (Key Management Server) is responsible for providing end-to-end encrypted keys and related security information for the MC Service Server (through the CSC-9 interface) and the GMS (through the CSC-10 interface). The corresponding client of the KMS is the Key Management Client (KMC), which communicates with the KMS through the CSC-8 interface.

[0205] However, the existing temporary group key distribution scheme has the following restrictive conditions:

[0206] It is only applicable to the key distribution of predefined dynamic recombination and is not applicable to other temporary groups;

[0207] Temporary group members need to belong to an existing group in advance, and the terminal has been distributed a default group key GMK by GMS;

[0208] Temporary group members must belong to a predefined default group, which is not suitable for initiating temporary group calls to users in different groups temporarily in emergency or special scenarios, and the applicable scenarios are relatively limited;

[0209] The terminal generates the security information (random number) of the group, which has a greater security risk compared with the security information generated by the service control server, and is easily stolen or tampered with; According to the existing standards, only in the case of single call can the terminal side generate security information, so it does not meet the functional requirements of centralized control for group services in the current architecture.

[0210] Based on the above, the embodiments of the present application provide a method, device, terminal and network side device for key transmission of a temporary group, so as to solve the problem that the key transmission method in the prior art cannot be compatible with the temporary group call based on predefined dynamic recombination and the temporary group call in Ad - hoc mode.

[0211] Among them, the method, device, terminal and network side device are based on the same application concept. Since the principles of solving problems by the method, device, terminal and network side device are similar, the implementation of the method, device, terminal and network side device can be referred to each other, and the repeated parts will not be elaborated.

[0212] As Figure 3 shown, a method for key transmission of a temporary group provided by the embodiments of the present application is executed by a network side device, including:

[0213] Step 301: When the first request sent by the first terminal meets the first preset condition, send a recombination request to the group management server GMS; wherein, the recombination request carries the temporary group member identification information corresponding to the first request.

[0214] Optionally, the recombination request also carries the temporary group key and the temporary group key identification corresponding to the first request.

[0215] In this step, when the first request received by the network device meets the first preset condition, the generation and distribution process of the temporary group key (i.e., T - GMK), the temporary group identification (i.e., T - GID) and the random number (i.e., RAND) can be triggered. Thus, as long as the first terminal sends a first request that meets the first preset condition to the network device, the generation and distribution of the security information required in the temporary group call can be completed by using the key transmission method of the temporary group in the embodiments of the present invention. Therefore, this method can be applied to different temporary group call models.

[0216] Step 302: Receive the first response information sent by the GMS according to the reorganization request; wherein, the first response information carries a temporary group identifier.

[0217] After receiving the reorganization request, the GMS can trigger the group key distribution process for the temporary group members and allocate a temporary group identifier (i.e., T-GID) to the temporary group. The GMS sends the first response information (i.e., Regroupnotification response) to the network-side device, and the first response information carries the T-GID.

[0218] Step 303: Generate a random number corresponding to the temporary group identifier, where the random number is used by the first terminal and the second terminal to determine the session key corresponding to the first request; wherein, the second terminal is the terminal corresponding to the temporary group member identification information.

[0219] The key transmission method provided by the embodiments of this application can directly trigger the generation and distribution of the temporary group key, random number, and temporary group identifier during the establishment process of a temporary group call, and can be applied to existing temporary group call models (including Ad-hoc temporary group calls and dynamic reorganization calls). Compared with existing technical solutions, it has a wider application range.

[0220] In the embodiments of this application, the network-side device can be an MCPTT Server, an MCVideo Server, or an MCService Server. It should be noted that when the network-side device is an MCPTT Server, the corresponding terminal is an MCPTTClient, the corresponding temporary group member identifier is an MCPTT ID, and the corresponding group identifier is an MCPTT Group ID; when the network-side device is an MCVideo Server, the corresponding terminal is an MCVideo Client, the corresponding temporary group member identifier is an MCVideoID, and the corresponding group identifier is an MCVideo Group ID; when the network-side device is an MC Service Server, the corresponding terminal is an MC Service Client, the corresponding temporary group member identifier is an MC Service ID, and the corresponding group identifier is an MCService Group ID. In the embodiments of this application, the case where the network-side device is an MCPTT Server and the terminal is an MCPTT Client is taken as an example for description.

[0221] It should also be noted that in the prior art, GMCs are all located on terminals, and the MCX Server does not have the logical function of GMC. However, in the network-side device (MCPTT Server) in the embodiments of the present application, logically, it can also include the client logical entity of GMS, that is, the Group Management Client (GMC).

[0222] In the embodiments of the present application, the first preset condition is one of the following:

[0223] The first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call;

[0224] The first request is a predefined dynamic reorganization request.

[0225] In this embodiment, when the first request meets the first preset condition, the generation and distribution process of the temporary group key (i.e., T-GMK), the temporary group identifier (i.e., T-GID), and the random number (i.e., RAND) can be triggered. Therefore, as long as the first terminal sends a first request that meets the first preset condition to the network device, the generation and distribution of the security information required in the temporary group call can be completed by using the temporary group key transmission method of the embodiments of the present invention, which can be applicable to different temporary group call models.

[0226] That is to say, in the embodiments of the present application, the network-side device (i.e., the MCX Server, such as the MCPTT Server, the MCVideo Server, or the MC Service Server) can directly trigger the generation and distribution of the temporary key by the call request type. Or, the network-side device can notify the GMS of the reorganization and trigger the GMS to send the group key information to the MCX Client.

[0227] In the embodiments of the present application, before sending a reorganization request to the Group Management Server GMS, the method further includes:

[0228] Sending a key material request to the Key Management Server KMS;

[0229] Receiving the second response information sent by the KMS according to the key material request; wherein, the second response information includes the temporary group key and the temporary group key identifier.

[0230] In this embodiment, by sending a key material request (i.e., Request for key material) to the KMS, the KMS can be requested to generate a temporary group key (i.e., T-GMK) corresponding to the first request, as well as a corresponding temporary key identifier (i.e., T-GMK ID), and can also generate configuration information related to the temporary group key (e.g., key update period, etc.). The KMS sends a response to the network device, that is, sends second response information to the network device, which may carry the T-GMK and T-GMK ID, and may also carry relevant configuration information.

[0231] In the embodiment of the present application, the call control entity (i.e., MCX Server, such as MCPTT Server, MCVideoServer or MC Service Server) determines session key related information (e.g., RAND), the key management entity (i.e., KMS) determines key information (i.e., T-GMK and T-GMK ID), and the group management entity (i.e., GMS) distributes group security information (e.g., T-GID). In this way, it conforms to the definition of entity roles in the existing architecture, can maximize the reuse of the functions of existing entities, has clear atomic functions, and strong business scalability.

[0232] The embodiment of the present invention is applicable to pulling any user into a temporary group, and these users do not need to be limited to belonging to the same group. Therefore, the scope of temporary group members in the embodiment of the present invention is larger than that of the existing solution, and thus can meet the needs of more scenarios (such as emergency calls).

[0233] In the embodiment of the present application, the first request carries the temporary group member identification information.

[0234] Here, the temporary group member identification information is the identification information of the call object of the temporary group call corresponding to the first request.

[0235] In the embodiment of the present application, when the first request is a first group call request, after generating a random number corresponding to the temporary group identifier, the method further includes:

[0236] Sending a second group call request to the second terminal; wherein, the second group call request carries the random number, the temporary group identifier, and the call type corresponding to the first group call request;

[0237] Receiving third response information sent by the second terminal according to the second group call request; wherein, the third response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request;

[0238] Send a fourth response message to the first terminal; wherein, the fourth response message is used to indicate that the temporary group call corresponding to the first request is successfully established; the fourth response message carries a temporary group identifier and a random number.

[0239] In this embodiment, for the temporary group call in the Ad-hoc mode, the network-side device can associate the temporary group members with the temporary group identifier (i.e., T-GID) (i.e., Affiliate user to group), that is, establish a group association relationship between the second terminal and the T-GID. The MCPTT Server sends a second group call request to the called temporary group members (i.e., the terminal corresponding to the temporary group member identifier information), and the second group call request carries RAND, T-GID, and Call type. When receiving the third response message sent by the second terminal, it is determined that the second terminal successfully joins the temporary group call. Send a fourth response message to the first terminal to inform the first terminal that the temporary group call corresponding to the first request is successfully established.

[0240] The following specifically illustrates the solution provided by the embodiments of the present application.

[0241] As Figure 4 shown, it is a schematic flowchart of the key transmission method in the embodiments of the present invention for the temporary group call in the Ad-hoc mode.

[0242] Step 1, the first terminal (such as MCPTT Client 1) initiates a group call request (i.e., Group call request) by sending a first request to a network device (such as MCPTT Server). Among them, the first request carries the temporary group member identifier information (i.e., MCPTT ID list, that is, Figure 4 the user list shown) and the call type (i.e., Call type). Here, the MCPTT ID list is the temporarily initiated group call object, that is, the group call object corresponding to the first request, and the call type indicates that the call type of this call (i.e., the first request) is the temporary group call in the Ad-hoc mode.

[0243] Here, the network-side device can be an MCPTT Server, an MCVideo Server, or an MC Service Server. It should be noted that when the network-side device is an MCPTT Server, the corresponding terminal is an MCPTT Client, the corresponding temporary group member identifier is an MCPTT ID, and the corresponding group identifier is an MCPTT Group ID; when the network-side device is an MCVideo Server, the corresponding terminal is an MCVideo Client, the corresponding temporary group member identifier is an MCVideo ID, and the corresponding group identifier is an MCVideo Group ID; when the network-side device is an MC Service Server, the corresponding terminal is an MC Service Client, the corresponding temporary group member identifier is an MC Service ID, and the corresponding group identifier is an MC Service Group ID. In the embodiments of the present application, the network-side device is an MCPTT Server and the terminal is an MCPTT Client as an example for illustration.

[0244] Step 2, the MCPTT Server determines whether to trigger a security process according to the call type. If the call type is an ad-hoc mode temporary group call, the first request meets the first preset condition, and the MCPTT Server sends a key request to the KMS.

[0245] Step 3, the MCPTT Server sends a key material request (i.e., Request for key material, initiate a key request) to the KMS.

[0246] Step 4, the KMS generates a temporary group key (i.e., T-GMK), and assigns a corresponding temporary key identifier (i.e., T-GMK ID) to the T-GMK. It can also generate configuration information related to the temporary group key (e.g., key update period, etc.). The KMS sends a response to the key material request from the MCPTT Server (i.e., Provision for key material), that is, sends the second response message, and this second response message carries the above information (i.e., T-GMK and T-GMK ID, and may also include related configuration information).

[0247] Step 5, the MCPTT Server sends a regroup notification (i.e., Regroup notification) to the GMS, that is, sends a regroup request to the GMS. The regroup request carries a list of temporary group member identifiers (MCPTT ID list), T-GMK, and T-GMK ID. Here, the T-GMK and its related information can be encrypted between the MCPTT Server and the GMS using a preset key (such as a pre-existing shared key).

[0248] Step 6, after receiving the regroup request, the GMS can trigger the process of distributing the group key to the temporary group members and assign a temporary group identifier (i.e., T-GID) to the temporary group. The GMS sends a group configuration request (i.e., Notify groupconfiguration request) to the first terminal (e.g., MCPTT Client 1) and the second terminal (e.g., MCPTT Client 2, MCPTT Client 3), as Figure 4 shown in 6a. The group configuration request carries T-GID, T-GMK, and T-GMK ID. After receiving the group configuration request, the first terminal and the second terminal send a group configuration notification response (i.e., Notify groupconfiguration response) to the GMS, as Figure 4 shown in 6b.

[0249] Step 7, the GMS responds to the regroup to the MCPTT Server, that is, sends the first response information (i.e., Regroup notification response) to the network-side device. The first response information carries T-GID. The MCPTT Server generates a random number (RAND) for this temporary group call.

[0250] Step 8, the MCPTT Server associates the temporary group members with the T-GID (i.e., Affiliate user togroup), that is, the MCPTT Server establishes a group association relationship between the second terminal and the T-GID.

[0251] Step 9, the MCPTT Server sends a group call request (i.e., the second group call request) to the called temporary group user (i.e., the terminal corresponding to the temporary group member identifier information). The second group call request carries RAND, T-GID, and Call type.

[0252] Step 10, the Client (i.e., the terminal) notifies the user that they are about to join the temporary group call.

[0253] Step 11, the Client sends a response (for example, the second terminal sends the third response message), and the third response message is used to indicate that the second terminal (such as MCPTT Client 2, MCPTT Client3) has successfully joined the temporary group call.

[0254] Step 12, the MCPTT Server generates a random number (i.e., RAND) for deriving the group call session key, sends a response to MCPTT Client 1, and carries the T-GID and RAND.

[0255] Step 13, the first terminal derives the session key for this temporary group call (i.e., Calculate session key) based on the second terminal's T-GID, T-GMK, and RAND, that is, determines the session key (i.e., session key) corresponding to the first request.

[0256] In the embodiment of the present application, when the first request is a predefined dynamic reorganization request, after generating the random number corresponding to the temporary group identifier, the method further includes:

[0257] Sending the predefined dynamic reorganization request to the second terminal;

[0258] Receiving the fifth response message sent by the second terminal according to the predefined dynamic reorganization request;

[0259] Establishing a group association relationship between the second terminal and the temporary group identifier;

[0260] Sending a sixth response message to the first terminal; wherein, the sixth response message carries the temporary group identifier and the random number.

[0261] In the embodiment of the present application, the method further includes:

[0262] Receiving a third group call request sent by the first terminal; wherein, the third group call request carries the temporary group identifier;

[0263] Sending a fourth group call request to the second terminal associated with the temporary group identifier; wherein, the fourth group call request carries the random number and the temporary group identifier;

[0264] Receiving a seventh response message sent by the second terminal according to the predefined dynamic reorganization request; wherein, the seventh response message is used to indicate that the second terminal has joined the temporary group call corresponding to the first request;

[0265] Sending an eighth response message to the first terminal; wherein, the eighth response message carries the temporary group identifier, and the eighth response message is used to indicate that the temporary group call has been successfully established.

[0266] In the embodiment of the present application, the MCX Server can generate key-related information (such as a random number) for a temporary group call and send this information to the MCX Client through a Group call request.

[0267] In the embodiment of the present application, the method further includes: when communicating with the GMS, encrypting the temporary group key and the temporary group key identifier using a preset key.

[0268] For example, the MCPTT Server and the GMS can encrypt the T-GMK and its related information using a pre-existing shared key.

[0269] The solution provided in the embodiment of the present application will be specifically illustrated below.

[0270] In an alternative embodiment of the present invention, for a temporary group call for dynamic reconfiguration based on a predefined group, the key transmission method for the temporary group can be divided into the following two processes: the dynamic reconfiguration process of the predefined group, and the group call process.

[0271] Among them, as Figure 6 shown, the process description of the dynamic reconfiguration of the predefined group is as follows:

[0272] Step 1, the first terminal (such as MCPTT client 1) determines the MCPTT user identification list (i.e., MCPTT ID list, temporary group member identification information) for dynamic reconfiguration and the group identification for reconfiguration (i.e., MCPTT Group ID).

[0273] Here, the user can be some or all of the users in the group identification.

[0274] Step 2, MCPTT client 1 sends a preconfigured dynamic reconfiguration request (i.e., Preconfigured regroup request) to the network-side device (such as MCPTT server), that is, MCPTT client 1 sends a first request to MCPTT server, and the first request is a preconfigured dynamic reconfiguration request. Among them, the preconfigured dynamic reconfiguration request carries the temporary group member identification information.

[0275] Here, the network-side device may be an MCPTT Server, an MCVideo Server, or an MC Service Server. It should be noted that when the network-side device is an MCPTT Server, the corresponding terminal is an MCPTT Client, the corresponding temporary group member identifier is an MCPTT ID, and the corresponding group identifier is an MCPTT Group ID; when the network-side device is an MCVideo Server, the corresponding terminal is an MCVideo Client, the corresponding temporary group member identifier is an MCVideo ID, and the corresponding group identifier is an MCVideo Group ID; when the network-side device is an MC Service Server, the corresponding terminal is an MC Service Client, the corresponding temporary group member identifier is an MC Service ID, and the corresponding group identifier is an MC Service Group ID. In the embodiments of the present application, the case where the network-side device is an MCPTT Server and the terminal is an MCPTT Client is taken as an example for illustration.

[0276] Step 3, after receiving the predefined dynamic reconfiguration request, the MCPTT Server triggers a security process to the KMS. The MCPTT server checks whether MCPTT client 1 has the permission to initiate the predefined dynamic reconfiguration request.

[0277] Step 4, if the MCPTT server determines that MCPTT client 1 has the permission to initiate the predefined dynamic reconfiguration, the MCPTT Server sends a key material request (i.e., Request for key material) to the KMS.

[0278] Step 5, the KMS generates a temporary group key (i.e., T-GMK), and assigns a corresponding temporary key identifier (i.e., T-GMK ID) to the T-GMK. It may also generate configuration information related to the temporary group key (such as the key update period, etc.). The KMS sends a response to the key material request (i.e., Provision for key material) to the MCPTT Server, that is, sends the second response information, and this second response information carries the above information (i.e., T-GMK and T-GMK ID, and may also include relevant configuration information).

[0279] Step 6, the MCPTT Server sends a regroup notification (i.e., Regroup notification) to the GMS, that is, sends a regroup request to the GMS. The regroup request carries a list of temporary group member identifiers (MCPTT ID list), T-GMK, and T-GMK ID. Here, the T-GMK and its related information can be encrypted between the MCPTT Server and the GMS using a preset key (such as a pre-existing shared key).

[0280] Step 7, after receiving the regroup request, the GMS can trigger the process of distributing the group key to the temporary group members and assign a temporary group identifier (T-GID) to the temporary group. The GMS sends a group configuration request (i.e., Notify group configuration request) to the first terminal (such as MCPTT Client 1) and the second terminal (such as MCPTT Client 2, MCPTT Client 3), as Figure 5 shown in 7a below. The group configuration request carries T-GID, T-GMK, and T-GMK ID. After receiving the group configuration request, the first terminal and the second terminal send a group configuration notification response (i.e., Notify group configuration response) to the GMS, as Figure 5 shown in 7b and 7c below.

[0281] Step 8, the GMS responds to the regroup to the MCPTT Server, that is, sends the first response information (i.e., Regroup notification response) to the network-side device. The first response information carries T-GID. The MCPTT Server generates a random number (RAND) for this temporary group call.

[0282] Step 9, the MCPTT Server generates a random number RAND for deriving the group call session key.

[0283] Step 10, the user (i.e., the terminal) that receives the group configuration request confirms to join the dynamic regroup.

[0284] Step 11, optionally, the received MCPTT clients accept the dynamic regroup request and send a response to the MCPTT server, that is, the second terminal sends the fifth response information according to the predefined dynamic regroup request.

[0285] Step 12, the MCPTT server establishes a group association relationship between the user of the dynamic regroup (i.e., the second terminal) and the temporary group identifier;

[0286] In step 13, the preconfigured regroup response (i.e., the sixth response message) sent by the MCPTT Server to the MCPTT client 1 carries the T-GID and RAND.

[0287] In step 14, the first terminal (e.g., MCPTT Client 1) and the second terminal (e.g., MCPTT Client 2, MCPTT Client 3) deduce the session key for subsequent ad hoc group calls (i.e., Calculate session key) based on the T-GID, T-GMK, and RAND, that is, determine the session key corresponding to the first request (i.e., session key).

[0288] After the preconfigured dynamic regrouping, the subsequent ad hoc group call process is as Figure 6 shown, and the process description of the group call is as follows:

[0289] In step 1, the MCPTT client 1 decides to initiate a group call to the users corresponding to the group identifier (i.e., MCPTT Group ID) (i.e., the second terminal, e.g., MCPTT client 2, MCPTT client 3).

[0290] In step 2, the MCPTT client 1 sends a third group call request (i.e., Group call request) to the MCPTT server based on the temporary group identifier (i.e., T-GID) obtained in the preconfigured dynamic regrouping process;

[0291] In step 3, the MCPTT server resolves the group ID to the GMS. It should be noted that this step is not involved in the ad hoc group call based on dynamic regrouping.

[0292] In step 4, the MCPTT server forwards the group call request to the MCPTT clients corresponding to the temporary group identifier, that is, sends a fourth group call request to the second terminal associated with the temporary group identifier. Among them, the MCPTT Server can carry the RAND through this fourth group call request, or it can not carry the RAND. It should also be noted that this RAND can be different from the RAND generated in the preconfigured dynamic regrouping process.

[0293] In step 5, the user who receives the call request confirms to join the ad hoc group call corresponding to the first request, that is, receives the seventh response message sent by the second terminal indicating that the second terminal has joined the ad hoc group call.

[0294] Step 6, the MCPTT clients that receive the call request accept the group call request and send the seventh response message to the MCPTT server. In Step 6, the Group call response carries the T-GID and the optional RAND.

[0295] Step 7, the MCPTT server sends the eighth response message to MCPTT client 1, indicating that the temporary group call is successfully established.

[0296] Step 8, the first terminal and the second terminal deduce the session key for this temporary group call (i.e., Calculate session key) based on the T-GID, T-GMK, and RAND of the second terminal, that is, determine the session key (i.e., sessionkey) corresponding to the first request.

[0297] Step 9, business data transmission is performed between the temporary group users (i.e., the first terminal and the second terminal related to this temporary group call).

[0298] In the key transmission method provided by the embodiment of the present application, the security information related to the temporary group service is generated by the service control server (i.e., the network-side device) and sent during the group call process, which is more in line with the definition of entity roles in the existing architecture and can be applied to the existing temporary group call models (including Ad-hoc temporary group calls and dynamic reorganization calls). Compared with the existing technical solutions, the application scope is wider.

[0299] As Figure 7 shown, the embodiment of the present application also provides a key transmission method for a temporary group, which is executed by a first terminal and includes:

[0300] Step 701: Send a first request to the network-side device; wherein, the first request carries the temporary group member identification information.

[0301] In this step, the first terminal initiates a group call request (i.e., Group call request) by sending a first request to a network device (such as an MCPTT Server).

[0302] Step 702: Receive the group configuration request sent by the GMS; wherein, the group configuration request carries the temporary group identification, the temporary group key, and the temporary group key identification, the group configuration request is sent according to the reorganization request sent by the network-side device, the reorganization request is sent by the network-side device when the first request meets the first preset condition, and the reorganization request carries the temporary group member identification information, the temporary group key, and the temporary group key identification corresponding to the first request;

[0303] Step 703: Obtain a random number, where the random number corresponds to the temporary group identifier in the first response message sent by the GMS, and the first response message is sent by the GMS according to the reorganization request sent by the network-side device;

[0304] Step 704: Determine the session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

[0305] In the embodiments of the present application, the network-side device may be an MCPTT Server, an MCVideo Server, or an MCService Server. It should be noted that when the network-side device is an MCPTT Server, the corresponding terminal is an MCPTTClient, the corresponding temporary group member identifier is an MCPTT ID, and the corresponding group identifier is an MCPTT Group ID; when the network-side device is an MCVideo Server, the corresponding terminal is an MCVideo Client, the corresponding temporary group member identifier is an MCVideoID, and the corresponding group identifier is an MCVideo Group ID; when the network-side device is an MC Service Server, the corresponding terminal is an MC Service Client, the corresponding temporary group member identifier is an MC Service ID, and the corresponding group identifier is an MCService Group ID. In the embodiments of the present application, the case where the network-side device is an MCPTT Server and the terminal is an MCPTT Client is taken as an example for illustration.

[0306] In the embodiments of the present application, the first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call; or, the first request is a predefined dynamic reorganization request.

[0307] In this embodiment, the specific situation when the first request is a first group call request may be: The first terminal sends a first request to a network device (such as an MCPTT Server) to initiate a group call request (i.e., a Group callrequest). Among them, the first request carries temporary group member identifier information (i.e., an MCPTT ID list) and a call type (i.e., a Call type). Here, the MCPTT ID list is the temporarily initiated group call object, that is, the group call object corresponding to the first request, and the call type indicates that the call type of this call (i.e., the first request) is an ad-hoc mode temporary group call.

[0308] When the first request is a predefined dynamic regrouping request, the specific situation may be as follows: The first terminal determines an MCPTT user identification list for dynamic regrouping (i.e., MCPTT ID list, temporary group member identification information) and a group identification for regrouping (i.e., MCPTT Group ID). Here, the user may be some or all of the users in the group identification. The first terminal sends a predefined dynamic regrouping request (i.e., Preconfigured regroup request) to the network-side device (such as an MCPTT server), that is, the first terminal sends a first request to the MCPTT server, and the first request is a predefined dynamic regrouping request. Among them, the predefined dynamic regrouping request carries temporary group member identification information.

[0309] In an embodiment of the present application, when the first request is a first group call request, the obtaining of the random number includes:

[0310] Receiving fourth response information sent by the network-side device; wherein, the fourth response information is used to indicate that the temporary group call corresponding to the first request is successfully established; the fourth response information carries a temporary group identification and a random number.

[0311] In an embodiment of the present application, when the first request is a predefined dynamic regrouping request, the obtaining of the random number includes:

[0312] Receiving sixth response information sent by the network-side device; wherein, the sixth response information carries a temporary group identification and a random number.

[0313] In an embodiment of the present application, after receiving the sixth response information sent by the network-side device, the method includes:

[0314] Sending a third group call request to the network-side device; wherein, the third group call request carries the temporary group identification;

[0315] Receiving eighth response information sent by the network-side device; wherein, the eighth response information carries a temporary group identification, and the eighth response information is used to indicate that the temporary group call is successfully established.

[0316] In an embodiment of the present application, after receiving the group configuration request sent by the GMS, the method further includes:

[0317] According to the group configuration request, sending a tenth response information to the GMS; wherein, the tenth response information is used to indicate that the first terminal has accepted the group configuration request.

[0318] In this embodiment, after the first terminal receives the group configuration request, it sends a group configuration notification response (i.e., Notify group configuration response) to the GMS, that is, it sends the tenth response message to the GMS to inform the GMS that the second terminal has accepted the group configuration request.

[0319] The key transmission method provided by the embodiments of the present application can trigger the generation and distribution process of the temporary group key, temporary group identifier, and random number by sending a first request that meets the first preset condition to the network-side device, so that it can be applicable to the existing temporary group call models (including Ad-hoc temporary group calls and dynamic reorganization calls). Compared with the existing technical solutions, the application scope is wider.

[0320] As Figure 8 shown, the embodiments of the present application also provide a key transmission method for a temporary group, which is executed by the second terminal and includes:

[0321] Step 801: Receive the group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to the reorganization request sent by the network-side device, the reorganization request is sent by the network-side device when the first request meets the first preset condition, and the reorganization request carries the temporary group member identifier information, temporary group key, and temporary group key identifier corresponding to the first request;

[0322] Step 802: Obtain a random number; wherein, the random number corresponds to the temporary group identifier in the first response message sent by the GMS, and the first response message is sent by the GMS according to the reorganization request sent by the network-side device;

[0323] Step 803: Determine the session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

[0324] In the embodiments of the present application, the second terminal can use the obtained temporary group identifier, temporary group key, temporary group key identifier, and random number to determine the session key of the temporary group call, so as to realize the trunking communication with other terminals.

[0325] In the embodiments of the present application, after receiving the group configuration request sent by the GMS, the method further includes:

[0326] Sending a ninth response message to the GMS according to the group configuration request; wherein, the ninth response message is used to indicate that the second terminal has accepted the group configuration request.

[0327] In this embodiment, after receiving the group configuration request, the second terminal sends a group configuration notification response (i.e., Notify group configuration response) to the GMS, that is, sends the ninth response information to the GMS to inform the GMS that the second terminal has accepted the group configuration request.

[0328] In the embodiment of the present application, the obtaining the random number includes:

[0329] Receiving a second group call request sent by a network side device; wherein, the second group call request carries a random number, the temporary group identifier, and a call type.

[0330] In the embodiment of the present application, the method further includes:

[0331] Sending a third response information to the network side device; wherein, the third response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request.

[0332] In this embodiment, the second terminal (such as MCPTT Client 2, MCPTT Client3) may send the third response information to inform the network side device that the second terminal has successfully joined the temporary group call.

[0333] Wherein, the method further includes:

[0334] Receiving a predefined dynamic reorganization request sent by a network side device;

[0335] According to the predefined dynamic reorganization request, sending a fifth response information to the network side device.

[0336] In this embodiment, the MCPTT clients that receive the predefined dynamic reorganization request may accept the dynamic reorganization request and send a response to the MCPTT server, that is, the second terminal sends the fifth response information according to the predefined dynamic reorganization request.

[0337] In the embodiment of the present application, the method further includes:

[0338] Receiving a fourth group call request sent by a network side device; wherein, the fourth group call request carries a random number and the temporary group identifier.

[0339] In the embodiment of the present application, the method further includes:

[0340] According to the fourth group call request, sending a seventh response information to the network side device; wherein, the seventh response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request.

[0341] In this embodiment, the second terminal (such as MCPTT Client 2 and MCPTT Client 3) can accept the group call request after receiving the call request, and send the seventh response message to the network device, informing the network device that the second terminal has successfully joined the temporary group call.

[0342] The key transmission method provided by the embodiment of the present application can determine the session key of the temporary group call by using the obtained temporary group identifier, temporary group key, temporary group key identifier, and random number, so as to realize trunking communication with other terminals.

[0343] As Figure 9 shown, the embodiment of the present application also provides a key transmission method for a temporary group, which is executed by the GMS and includes:

[0344] Step 901: Receive a regroup request sent by a network device; wherein, the regroup request carries temporary group member identification information, a temporary group key, and a temporary group key identifier;

[0345] Step 902: According to the regroup request, send a group configuration request to the first terminal and the second terminal corresponding to the temporary group member identification information; wherein, the group configuration request carries a temporary group identifier, the temporary group key, and the temporary group key identifier.

[0346] In this step, after the GMS receives the regroup request (i.e., Regroup notification), it can trigger the process of distributing the group key of the temporary group members (i.e., the temporary group key corresponding to the first request) and allocate a temporary group identifier (T-GID) to the temporary group. The GMS sends a group configuration request (i.e., Notify group configuration request) to the first terminal (such as MCPTT Client 1) and the second terminal (such as MCPTT Client 2 and MCPTT Client 3). This group configuration request carries T-GID, T-GMK, and T-GMK ID. In this way, after receiving the group configuration request, the first terminal and the second terminal can send a group configuration notification response (i.e., Notify group configuration response) to the GMS.

[0347] Step 903: Receive the ninth response message sent by the second terminal according to the group configuration request, and receive the tenth response message sent by the first terminal according to the group configuration request.

[0348] In this step, after receiving the corresponding response messages fed back by the first terminal and the second terminal according to the group configuration request, it can be determined that the terminal has accepted the group configuration request.

[0349] Step 904: Send a first response message to the network side device; wherein, the first response message carries a temporary group identifier.

[0350] In this step, GMS responds to the network side device (such as MCPTT Server) for regrouping, that is, sends a first response message (i.e., Regroup notification response) to the network side device, and the first response message carries the T-GID. MCPTTServer generates a random number (RAND) for this temporary group call.

[0351] In the embodiments of the present application, the network side device may be an MCPTT Server, an MCVideo Server, or an MCService Server. It should be noted that when the network side device is an MCPTT Server, the corresponding terminal is an MCPTTClient, the corresponding temporary group member identifier is an MCPTT ID, and the corresponding group identifier is an MCPTT Group ID; when the network side device is an MCVideo Server, the corresponding terminal is an MCVideo Client, the corresponding temporary group member identifier is an MCVideoID, and the corresponding group identifier is an MCVideo Group ID; when the network side device is an MC Service Server, the corresponding terminal is an MC Service Client, the corresponding temporary group member identifier is an MC Service ID, and the corresponding group identifier is an MCService Group ID. In the embodiments of the present application, the case where the network side device is an MCPTT Server and the terminal is an MCPTT Client is taken as an example for illustration.

[0352] In the embodiments of the present application, the method further includes:

[0353] When communicating with the network side device, encrypt the temporary group key and the temporary group key identifier by using a preset key.

[0354] For example, a pre-existing shared key can be used between GMS and MCPTT Server to encrypt the T-GMK and its related information.

[0355] In the key transmission method provided by the embodiments of the present application, the temporary group identifier is generated and distributed in GMS, which is more in line with the definition of entity roles in the existing architecture, can be applied to the existing temporary group call models (including Ad-hoc temporary group calls and dynamic regrouping calls), and has a wider application range compared with the existing technical solutions.

[0356] Such as Figure 10As shown in the figure, an embodiment of the present application further provides a key transmission method for a temporary group, which is executed by the KMS and includes:

[0357] Step 1001: Receive a key material request sent by a network-side device;

[0358] Step 1002: Send second response information to the network-side device; wherein, the second response information includes a temporary group key and its corresponding temporary group key identifier.

[0359] In the embodiment of the invention, after receiving a key material request (i.e., Request for key material) sent by a network-side device, the KMS can generate a temporary group key (i.e., T-GMK), allocate a corresponding temporary key identifier (i.e., T-GMK ID) for the T-GMK, and can also generate configuration information related to the temporary group key (e.g., key update period, etc.), and send a response to the key material request (i.e., Provision for key material) to the MCPTT Server, that is, send second response information, and the second response information carries the above information (i.e., T-GMK and T-GMK ID, and may also include relevant configuration information).

[0360] In the embodiment of the present application, the network-side device may be an MCPTT Server, an MCVideo Server, or an MCService Server. It should be noted that when the network-side device is an MCPTT Server, the corresponding terminal is an MCPTT Client, the corresponding temporary group member identifier is an MCPTT ID, and the corresponding group identifier is an MCPTT Group ID; when the network-side device is an MCVideo Server, the corresponding terminal is an MCVideo Client, the corresponding temporary group member identifier is an MCVideo ID, and the corresponding group identifier is an MCVideo Group ID; when the network-side device is an MC Service Server, the corresponding terminal is an MC Service Client, the corresponding temporary group member identifier is an MC Service ID, and the corresponding group identifier is an MCService Group ID. In the embodiment of the present application, the case where the network-side device is an MCPTT Server and the terminal is an MCPTT Client is taken as an example for illustration.

[0361] For the key transmission method provided in the embodiment of the present application, the relevant security information of the temporary group is generated in the KMS, which more conforms to the definition of entity roles in the existing architecture, and can be applied to the existing temporary group call models (including Ad-hoc temporary group calls and dynamic reconfiguration calls). Compared with the existing technical solutions, the application scope is wider.

[0362] As Figure 11 shown, an embodiment of the present application further provides a network - side device, including a memory 1101, a transceiver 1102, and a processor 1103:

[0363] The memory 1101 is used to store a computer program; the transceiver 1102 is used to send and receive data under the control of the processor 1103; the processor 1103 is used to read the computer program in the memory 1101 and perform the following operations:

[0364] When the first request sent by the first terminal meets the first preset condition, send a reorganization request to the Group Management Server (GMS); wherein, the reorganization request carries the temporary group member identification information corresponding to the first request;

[0365] Receive the first response information sent by the GMS according to the reorganization request; wherein, the first response information carries a temporary group identifier;

[0366] Generate a random number corresponding to the temporary group identifier, and the random number is used for the first terminal and the second terminal to determine the session key corresponding to the first request; wherein, the second terminal is the terminal corresponding to the temporary group member identification information.

[0367] Specifically, the transceiver 1102 is used to receive and send data under the control of the processor 1103.

[0368] Wherein, in Figure 11 , the bus architecture may include any number of interconnected buses and bridges. Specifically, various circuits of one or more processors represented by the processor 1103 and the memory represented by the memory 1101 are linked together. The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art. Therefore, they will not be further described herein. The bus interface provides an interface. The transceiver 1102 can be multiple elements, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on a transmission medium, and these transmission mediums include wireless channels, wired channels, optical fiber cables, etc. The processor 1103 is responsible for managing the bus architecture and general processing, and the memory 1101 can store the data used by the processor 1103 when performing operations.

[0369] The processor 1103 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor may also adopt a multi-core architecture.

[0370] Wherein, before sending a reorganization request to the group management server GMS, the method further includes:

[0371] Sending a key material request to the key management server KMS;

[0372] Receiving second response information sent by the KMS according to the key material request; wherein, the second response information includes a temporary group key and a temporary group key identifier.

[0373] Wherein, the first request carries the temporary group member identification information.

[0374] Wherein, the first preset condition is one of the following:

[0375] The first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call;

[0376] The first request is a predefined dynamic reorganization request.

[0377] Wherein, when the first request is a first group call request, after generating a random number corresponding to the temporary group identifier, the processor is further configured to read a computer program in the memory and perform the following operations:

[0378] Sending a second group call request to the second terminal; wherein, the second group call request carries the random number, the temporary group identifier, and the call type corresponding to the first group call request;

[0379] Receiving third response information sent by the second terminal according to the second group call request; wherein, the third response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request;

[0380] Sending fourth response information to the first terminal; wherein, the fourth response information is used to indicate that the temporary group call corresponding to the first request is successfully established; the fourth response information carries a temporary group identifier and a random number.

[0381] Wherein, when the first request is a predefined dynamic reorganization request, after generating a random number corresponding to the temporary group identifier, the processor is further configured to read a computer program in the memory and perform the following operations:

[0382] Send the predefined dynamic reorganization request to the second terminal;

[0383] Receive a fifth response message sent by the second terminal according to the predefined dynamic reorganization request;

[0384] Establish a group association relationship between the second terminal and the temporary group identifier;

[0385] Send a sixth response message to the first terminal; wherein, the sixth response message carries the temporary group identifier and the random number.

[0386] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0387] Receive a third group call request sent by the first terminal; wherein, the third group call request carries the temporary group identifier;

[0388] Send a fourth group call request to the second terminal associated with the temporary group identifier; wherein, the fourth group call request carries the random number and the temporary group identifier;

[0389] Receive a seventh response message sent by the second terminal according to the predefined dynamic reorganization request; wherein, the seventh response message is used to indicate that the second terminal has joined the temporary group call corresponding to the first request;

[0390] Send an eighth response message to the first terminal; wherein, the eighth response message carries the temporary group identifier, and the eighth response message is used to indicate that the temporary group call is successfully established.

[0391] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0392] When communicating with the GMS, encrypt the temporary group key and the temporary group key identifier using a preset key.

[0393] The network-side device provided by the embodiments of the present application generates the security information related to the temporary group service in the service control server (i.e., the network-side device) and distributes it during the group call process, which is more in line with the definition of the entity role in the existing architecture and can be applied to the existing temporary group call models (including Ad-hoc temporary group calls and dynamic reorganization calls). Compared with the existing technical solutions, the application scope is wider.

[0394] Such as Figure 12As shown, an embodiment of the present application further provides a terminal, which is a first terminal and includes a memory 1220, a transceiver 1210, and a processor 1200:

[0395] The memory 1220 is used to store computer programs; the transceiver 1210 is used to transmit and receive data under the control of the processor 1200; the processor 1200 is used to read the computer programs in the memory 1220 and perform the following operations:

[0396] Send a first request to a network-side device; wherein, the first request carries temporary group member identification information;

[0397] Receive a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, and the group configuration request is sent according to a reorganization request sent by the network-side device, and the reorganization request is sent by the network-side device when the first request meets a first preset condition, and the reorganization request carries the temporary group member identification information, the temporary group key, and the temporary group key identifier corresponding to the first request;

[0398] Obtain a random number; wherein, the random number corresponds to the temporary group identifier in the first response information sent by the GMS, and the first response information is sent by the GMS according to the reorganization request sent by the network-side device;

[0399] Determine the session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

[0400] Specifically, the transceiver 1210 is used to receive and transmit data under the control of the processor 1200.

[0401] Among them, in Figure 12 The bus architecture may include any number of interconnected buses and bridges. Specifically, various circuits represented by one or more processors represented by the processor 1200 and the memory represented by the memory 1220 are linked together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art. Therefore, they will not be further described herein. The bus interface provides an interface. The transceiver 1210 may be multiple elements, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on a transmission medium, and these transmission mediums include wireless channels, wired channels, optical cables, and other transmission mediums. For different user devices, the user interface 1230 may also be an interface capable of externally connecting and internally connecting required devices, and the connected devices include but are not limited to a keypad, a display, a speaker, a microphone, a joystick, etc.

[0402] The processor 1200 is responsible for managing the bus architecture and general processing, and the memory 1220 can store data used by the processor 600 when executing operations.

[0403] Optionally, the processor 1200 can be a CPU (Central Processing Unit), ASIC (Application Specific Integrated Circuit), FPGA (Field-Programmable Gate Array), or CPLD (Complex Programmable Logic Device). The processor can also adopt a multi-core architecture.

[0404] The processor is used to execute any of the methods provided in the embodiments of the present application according to the obtained executable instructions by calling the computer program stored in the memory. The processor and the memory can also be physically separated.

[0405] Wherein, the first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call; or,

[0406] The first request is a predefined dynamic reorganization request.

[0407] Wherein, when the first request is a first group call request, the processor is further used to read the computer program in the memory and perform the following operations:

[0408] Receive the fourth response information sent by the network-side device; wherein, the fourth response information is used to indicate that the temporary group call corresponding to the first request is successfully established; the fourth response information carries a temporary group identifier and a random number.

[0409] Wherein, when the first request is a predefined dynamic reorganization request, the processor is further used to read the computer program in the memory and perform the following operations:

[0410] Receive the sixth response information sent by the network-side device; wherein, the sixth response information carries a temporary group identifier and a random number.

[0411] Wherein, after receiving the sixth response information sent by the network-side device, the processor is further used to read the computer program in the memory and perform the following operations:

[0412] Send a third group call request to the network-side device; wherein, the third group call request carries the temporary group identifier;

[0413] Receive the eighth response message sent by the network-side device; wherein, the eighth response message carries a temporary group identifier, and the eighth response message is used to indicate that the establishment of the temporary group call is successful.

[0414] Wherein, after receiving the group configuration request sent by the GMS, the processor is further configured to read the computer program in the memory and perform the following operations:

[0415] According to the group configuration request, send a tenth response message to the GMS; wherein, the tenth response message is used to indicate that the first terminal has accepted the group configuration request.

[0416] The terminal provided in the embodiment of the present application can trigger the generation and distribution process of the temporary group key, the temporary group identifier, and the random number by sending a first request that meets the first preset condition to the network-side device, so that it can be applicable to the existing temporary group call models (including Ad-hoc temporary group call and dynamic reorganization call). Compared with the existing technical solutions, the application range is wider.

[0417] As Figure 12 shown, the embodiment of the present application also provides a terminal, the terminal is a second terminal, including a memory 1220, a transceiver 1210, and a processor 1200:

[0418] The memory 1220 is used to store a computer program; the transceiver 1210 is used to receive and send data under the control of the processor 1200; the processor 1200 is used to read the computer program in the memory 1220 and perform the following operations:

[0419] Receive a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to a reorganization request sent by the network-side device, the reorganization request is sent by the network-side device when the first request meets the first preset condition, and the reorganization request carries the temporary group member identifier information, the temporary group key, and the temporary group key identifier corresponding to the first request;

[0420] Obtain a random number; wherein, the random number corresponds to the temporary group identifier in the first response message sent by the GMS, and the first response message is sent by the GMS according to the reorganization request sent by the network-side device;

[0421] Determine the session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

[0422] Specifically, the transceiver 1210 is configured to receive and send data under the control of the processor 1200.

[0423] Among them, in Figure 12 , the bus architecture may include any number of interconnected buses and bridges, specifically, various circuits of one or more processors represented by processor 1200 and memories represented by memory 1220 are linked together. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, etc., which are well known in the art, and thus will not be further described herein. The bus interface provides an interface. The transceiver 1210 may be multiple components, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on a transmission medium, and these transmission mediums include wireless channels, wired channels, optical fiber cables, and other transmission mediums. For different user devices, the user interface 1230 may also be an interface capable of externally connecting and internally connecting required devices, and the connected devices include but are not limited to a keypad, a display, a speaker, a microphone, a joystick, etc.

[0424] The processor 1200 is responsible for managing the bus architecture and general processing, and the memory 1220 may store data used by the processor 600 when performing operations.

[0425] Optionally, the processor 1200 may be a CPU (Central Processing Unit), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a CPLD (Complex Programmable Logic Device), and the processor may also adopt a multi-core architecture.

[0426] The processor is used to execute any of the methods provided in the embodiments of the present application according to the obtained executable instructions by calling the computer program stored in the memory. The processor and the memory may also be physically separated.

[0427] Among them, after receiving the group configuration request sent by the GMS, the processor is further used to read the computer program in the memory and perform the following operations:

[0428] According to the group configuration request, send a ninth response message to the GMS; wherein, the ninth response message is used to indicate that the second terminal has accepted the group configuration request.

[0429] Among them, the processor is further used to read the computer program in the memory and perform the following operations:

[0430] Receive a second group call request sent by a network-side device; wherein, the second group call request carries a random number, the temporary group identifier, and a call type.

[0431] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0432] Send a third response message to the network-side device; wherein, the third response message is used to indicate that the second terminal has joined the temporary group call corresponding to the first request.

[0433] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0434] Receive a predefined dynamic reorganization request sent by a network-side device;

[0435] Send a fifth response message to the network-side device according to the predefined dynamic reorganization request.

[0436] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0437] Receive a fourth group call request sent by a network-side device; wherein, the fourth group call request carries a random number and the temporary group identifier.

[0438] Wherein, the processor is further configured to read a computer program in the memory and perform the following operations:

[0439] Send a seventh response message to the network-side device according to the fourth group call request; wherein, the seventh response message is used to indicate that the second terminal has joined the temporary group call corresponding to the first request.

[0440] The terminal provided in the embodiments of the present application can use the obtained temporary group identifier, temporary group key, temporary group key identifier, and random number to determine the session key of the temporary group call, so as to implement trunking communication with other terminals.

[0441] The embodiments of the present application further provide a GMS, which may adopt the same structure as shown in Figure 11 including a memory 1101, a transceiver 1102, and a processor 1103:

[0442] The memory 1101 is used to store a computer program; the transceiver 1102 is used to transmit and receive data under the control of the processor 1103; the processor 1103 is used to read the computer program in the memory 1101 and perform the following operations:

[0443] Receive a reorganization request sent by a network-side device; wherein, the reorganization request carries temporary group member identification information, a temporary group key, and a temporary group key identifier;

[0444] According to the reorganization request, send a group configuration request to a first terminal and a second terminal corresponding to the temporary group member identification information; wherein, the group configuration request carries a temporary group identifier, the temporary group key, and the temporary group key identifier;

[0445] Receive a ninth response message sent by the second terminal according to the group configuration request, and receive a tenth response message sent by the first terminal according to the group configuration request;

[0446] Send a first response message to the network-side device; wherein, the first response message carries a temporary group identifier.

[0447] Specifically, the transceiver 1102 is used to receive and send data under the control of the processor 1103.

[0448] Among them, in Figure 11 the bus architecture may include any number of interconnected buses and bridges, specifically, various circuits represented by one or more processors represented by the processor 1103 and a memory represented by the memory 1101 are linked together. The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, and therefore, will not be further described herein. The bus interface provides an interface. The transceiver 1102 may be multiple elements, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on a transmission medium, and these transmission mediums include wireless channels, wired channels, optical fiber cables, and other transmission mediums. The processor 1103 is responsible for managing the bus architecture and general processing, and the memory 1101 can store data used by the processor 1103 when executing operations.

[0449] The processor 1103 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD), and the processor may also adopt a multi-core architecture.

[0450] Among them, the processor is further used to read a computer program in the memory and perform the following operations:

[0451] When communicating with the network-side device, encrypt the temporary group key and the temporary group key identifier by using a preset key.

[0452] In the GMS provided by the embodiments of the present application, the temporary group identifier is generated and distributed in the GMS, which more conforms to the definition of entity roles in the existing architecture and can be applied to the existing temporary group call models (including Ad-hoc temporary group calls and dynamic reorganization calls). Compared with the existing technical solutions, the application scope is wider.

[0453] The embodiments of the present application also provide a KMS, which may adopt the same structure as shown in Figure 11 including a memory 1101, a transceiver 1102, and a processor 1103:

[0454] The memory 1101 is used to store computer programs; the transceiver 1102 is used to receive and send data under the control of the processor 1103; the processor 1103 is used to read the computer programs in the memory 1101 and perform the following operations:

[0455] Receive a key material request sent by the network-side device;

[0456] Send second response information to the network-side device; wherein, the second response information includes a temporary group key and its corresponding temporary group key identifier.

[0457] Specifically, the transceiver 1102 is used to receive and send data under the control of the processor 1103.

[0458] Among them, in Figure 11 the bus architecture may include any number of interconnected buses and bridges, specifically, various circuits represented by one or more processors represented by the processor 1103 and a memory represented by the memory 1101 are linked together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art. Therefore, they will not be further described herein. The bus interface provides an interface. The transceiver 1102 may be multiple components, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on a transmission medium, and these transmission media include wireless channels, wired channels, optical fiber cables, and other transmission media. The processor 1103 is responsible for managing the bus architecture and general processing, and the memory 1101 can store the data used by the processor 1103 when performing operations.

[0459] The processor 1103 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor may also adopt a multi-core architecture.

[0460] In the embodiment of the present application, the relevant security information of the temporary group is generated in the KMS, which is more in line with the definition of entity roles in the existing architecture and can be applied to the existing temporary group call models (including Ad-hoc temporary group calls and dynamic reorganization calls). Compared with the existing technical solutions, the application scope is wider.

[0461] As Figure 13 shown, the embodiment of the present application further provides a key transmission device, which is applied to a network-side device and includes:

[0462] A first request unit 131, configured to send a reorganization request to a group management server GMS when a first request sent by a first terminal meets a first preset condition; wherein, the reorganization request carries temporary group member identification information corresponding to the first request;

[0463] A first receiving unit 132, configured to receive first response information sent by the GMS according to the reorganization request; wherein, the first response information carries a temporary group identifier;

[0464] A first generating unit 133, configured to generate a random number corresponding to the temporary group identifier, and the random number is used for the first terminal and a second terminal to determine a session key corresponding to the first request; wherein, the second terminal is a terminal corresponding to the temporary group member identification information.

[0465] In the embodiment of the present application, the key transmission device further includes:

[0466] A key request unit, configured to send a key material request to a key management server KMS;

[0467] A key receiving unit, configured to receive second response information sent by the KMS according to the key material request; wherein, the second response information includes a temporary group key and a temporary group key identifier.

[0468] In the embodiment of the present application, the first request carries the temporary group member identification information.

[0469] In the embodiment of the present application, the first preset condition is one of the following:

[0470] The first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call;

[0471] The first request is a predefined dynamic reorganization request.

[0472] In an embodiment of the present application, the key transmission device further includes:

[0473] A second group call unit, configured to send a second group call request to the second terminal; wherein, the second group call request carries the random number, the temporary group identifier, and the call type corresponding to the first group call request;

[0474] A sixth receiving unit, configured to receive third response information sent by the second terminal according to the second group call request; wherein, the third response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request;

[0475] A first sending unit, configured to send fourth response information to the first terminal; wherein, the fourth response information is used to indicate that the temporary group call corresponding to the first request is successfully established; the fourth response information carries a temporary group identifier and a random number.

[0476] In an embodiment of the present application, the key transmission device further includes:

[0477] A reorganization request unit, configured to send the predefined dynamic reorganization request to the second terminal;

[0478] A seventh receiving unit, configured to receive fifth response information sent by the second terminal according to the predefined dynamic reorganization request;

[0479] An association establishment unit, configured to establish a group association relationship between the second terminal and the temporary group identifier;

[0480] A third sending unit, configured to send sixth response information to the first terminal; wherein, the sixth response information carries a temporary group identifier and a random number.

[0481] In an embodiment of the present application, the key transmission device further includes:

[0482] An eighth receiving unit, configured to receive a third group call request sent by the first terminal; wherein, the third group call request carries the temporary group identifier;

[0483] A fourth sending unit, configured to send a fourth group call request to the second terminal associated with the temporary group identifier; wherein, the fourth group call request carries the random number and the temporary group identifier;

[0484] A ninth receiving unit, configured to receive seventh response information sent by the second terminal according to the predefined dynamic reorganization request; wherein, the seventh response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request;

[0485] A fifth sending unit, configured to send eighth response information to the first terminal; wherein, the eighth response information carries a temporary group identifier, and the eighth response information is used to indicate that the temporary group call is successfully established.

[0486] In the embodiments of the present application, the key transmission device further includes:

[0487] A first encryption unit, configured to encrypt the temporary group key and the temporary group key identifier by using a preset key when communicating with the GMS.

[0488] It should be noted here that the above device provided in the embodiments of the present application can implement all the method steps implemented by the key transmission method embodiments of the above network-side device, and can achieve the same technical effects. The same parts and beneficial effects as those in the method embodiments will not be specifically described in this embodiment.

[0489] In the key transmission device provided in the embodiments of the present application, the temporary group service-related security information is generated by the service control server (i.e., the network-side device) and is sent down during the group call process, which is more in line with the definition of entity roles in the existing architecture, and can be applied to the existing temporary group call models (including Ad-hoc temporary group calls and dynamic reorganization calls). Compared with the existing technical solutions, the application scope is wider.

[0490] As Figure 14 shown, the embodiments of the present application further provide a key transmission device, which is applied to a first terminal and includes:

[0491] A first call unit 141, configured to send a first request to a network-side device; wherein, the first request carries temporary group member identification information;

[0492] A first reorganization unit 142, configured to receive a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to a reorganization request sent by the network-side device, the reorganization request is sent by the network-side device when the first request meets a first preset condition, and the reorganization request carries the temporary group member identification information, the temporary group key, and the temporary group key identifier corresponding to the first request;

[0493] The first acquisition unit 143 is configured to acquire a random number, where the random number corresponds to a temporary group identifier in the first response message sent by the GMS, and the first response message is sent by the GMS according to a reorganization request sent by the network-side device;

[0494] The first determination unit 144 is configured to determine a session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

[0495] In an embodiment of the present application, the first request is a first group call request, and a call type corresponding to the first group call request is an ad-hoc mode temporary group call; or, the first request is a predefined dynamic reorganization request.

[0496] In an embodiment of the present application, the first acquisition unit 143 includes:

[0497] The first receiving subunit is configured to receive a fourth response message sent by the network-side device, where the fourth response message is used to indicate that a temporary group call corresponding to the first request is successfully established, and the fourth response message carries a temporary group identifier and a random number.

[0498] In an embodiment of the present application, the first acquisition unit 143 includes:

[0499] The second receiving subunit is configured to receive a sixth response message sent by the network-side device, where the sixth response message carries a temporary group identifier and a random number.

[0500] In an embodiment of the present application, the key transmission device further includes:

[0501] The sixth sending unit is configured to send a third group call request to the network-side device, where the third group call request carries the temporary group identifier;

[0502] The tenth receiving unit is configured to receive an eighth response message sent by the network-side device, where the eighth response message carries a temporary group identifier, and the eighth response message is used to indicate that a temporary group call is successfully established.

[0503] In an embodiment of the present application, the key transmission device further includes:

[0504] The seventh sending unit is configured to send a tenth response message to the GMS according to the group configuration request, where the tenth response message is used to indicate that the first terminal has accepted the group configuration request.

[0505] It should be noted here that the above device provided by the embodiments of the present application can implement all the method steps implemented by the above method embodiments on the first terminal side, and can achieve the same technical effects. Therefore, the same parts and beneficial effects as those in the method embodiments will not be specifically described in this embodiment.

[0506] The key transmission method provided by the embodiments of the present application can trigger the generation and distribution process of the temporary group key, the temporary group identifier, and the random number by sending a first request that meets the first preset condition to the network-side device. Therefore, it can be applied to the existing temporary group call models (including Ad-hoc temporary group calls and dynamic reconfiguration calls), and has a wider application range compared with the existing technical solutions.

[0507] As Figure 15 shown, the embodiments of the present application also provide a key transmission device, which is applied to the second terminal and includes:

[0508] A second receiving unit 151, configured to receive a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, and the group configuration request is sent according to a reconfiguration request sent by the network-side device, and the reconfiguration request is sent by the network-side device when the first request meets the first preset condition, and the reconfiguration request carries the temporary group member identifier information, the temporary group key, and the temporary group key identifier corresponding to the first request;

[0509] A second obtaining unit 152, configured to obtain a random number; wherein, the random number corresponds to the temporary group identifier in the first response information sent by the GMS, and the first response information is sent by the GMS according to the reconfiguration request sent by the network-side device;

[0510] A second determining unit 153, configured to determine the session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

[0511] In the embodiments of the present application, the key transmission device further includes:

[0512] An eighth sending unit, configured to send a ninth response information to the GMS according to the group configuration request; wherein, the ninth response information is used to indicate that the second terminal has accepted the group configuration request.

[0513] In the embodiments of the present application, the second obtaining unit 152 includes:

[0514] A second receiving subunit, configured to receive a second group call request sent by the network-side device; wherein, the second group call request carries a random number, the temporary group identifier, and a call type.

[0515] In the embodiments of the present application, the key transmission device further includes:

[0516] A ninth sending unit, configured to send third response information to the network-side device; wherein, the third response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request.

[0517] In the embodiments of the present application, the key transmission device further includes:

[0518] An eleventh receiving unit, configured to receive a predefined dynamic reorganization request sent by the network-side device;

[0519] A tenth sending unit, configured to send fifth response information to the network-side device according to the predefined dynamic reorganization request.

[0520] In the embodiments of the present application, the second obtaining unit 152 includes:

[0521] A third receiving subunit, configured to receive a fourth group call request sent by the network-side device; wherein, the fourth group call request carries a random number and the temporary group identifier.

[0522] In the embodiments of the present application, the key transmission device further includes:

[0523] An eleventh sending unit, configured to send seventh response information to the network-side device according to the fourth group call request; wherein, the seventh response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request.

[0524] It should be noted here that the above device provided in the embodiments of the present application can implement all the method steps implemented by the key transmission method embodiment on the second terminal side, and can achieve the same technical effects. Therefore, the same parts and beneficial effects as those in the method embodiment will not be specifically described in this embodiment.

[0525] The key transmission method provided in the embodiments of the present application can determine the session key of the temporary group call by using the obtained temporary group identifier, temporary group key, temporary group key identifier, and random number, so as to implement trunking communication with other terminals.

[0526] As Figure 16 shown, the embodiments of the present application further provide a key transmission device, which is applied to GMS and includes:

[0527] A fourth receiving unit 161, configured to receive a reorganization request sent by the network-side device; wherein, the reorganization request carries temporary group member identification information, a temporary group key, and a temporary group key identifier;

[0528] A second sending unit 162, configured to send a group configuration request to a first terminal and a second terminal corresponding to the temporary group member identification information according to the recombination request; wherein, the group configuration request carries a temporary group identifier, the temporary group key, and the temporary group key identifier.

[0529] A fifth receiving unit 163, configured to receive a ninth response message sent by the second terminal according to the group configuration request, and receive a tenth response message sent by the first terminal according to the group configuration request.

[0530] A first response unit 164, configured to send a first response message to the network-side device; wherein, the first response message carries a temporary group identifier.

[0531] In an embodiment of the present application, the key transmission device further includes:

[0532] A second encryption unit, configured to encrypt the temporary group key and the temporary group key identifier by using a preset key when communicating with the network-side device.

[0533] It should be noted here that the above device provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned key transmission method embodiment on the GMS side, and can achieve the same technical effects. The same parts and beneficial effects as those in the method embodiment will not be specifically described in this embodiment.

[0534] In the key transmission device provided in the embodiment of the present application, the temporary group identifier is generated and sent down in the GMS, which more conforms to the definition of the entity role in the existing architecture, and can be applied to the existing temporary group call models (including Ad-hoc temporary group calls and dynamic recombination calls). Compared with the existing technical solutions, the application range is wider.

[0535] As Figure 17 shown, the embodiment of the present application further provides a key transmission device, which is applied to the KMS and includes:

[0536] A third receiving unit 171, configured to receive a key material request sent by a network-side device.

[0537] A second response unit 172, configured to send a second response message to the network-side device; wherein, the second response message includes a temporary group key and its corresponding temporary group key identifier.

[0538] It should be noted here that the above device provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned key transmission method embodiment on the KMS side, and can achieve the same technical effects. The same parts and beneficial effects as those in the method embodiment will not be specifically described in this embodiment.

[0539] In the key transmission device provided by the embodiment of the present application, the relevant security information of the temporary group is generated in the KMS, which more conforms to the definition of entity roles in the existing architecture and can be applied to the existing temporary group call models (including Ad-hoc temporary group calls and dynamic reconfiguration calls). Compared with the existing technical solutions, the application scope is wider.

[0540] It should be noted that the division of units in the embodiments of the present application is illustrative, merely a logical function division. In actual implementation, there may be other division methods. In addition, in each embodiment of the present application, each functional unit may be integrated in a processing unit, or each unit may exist physically alone, or two or more units may be integrated in one unit. The above-mentioned integrated units may be implemented in the form of hardware or in the form of software functional units.

[0541] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a processor-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the existing technology, or all or part of this technical solution, may be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in the embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0542] The embodiment of the present application also provides a processor-readable storage medium. The processor-readable storage medium stores a computer program, and the computer program is used to cause the processor to execute the above-mentioned key transmission method on the network side device side; or the computer program is used to cause the processor to execute the above-mentioned key transmission method on the KMS side; or the computer program is used to cause the processor to execute the above-mentioned key transmission method on the first terminal side; or the computer program is used to cause the processor to execute the above-mentioned key transmission method on the second terminal side; or the computer program is used to cause the processor to execute the above-mentioned key transmission method on the GMS side.

[0543] The processor-readable storage medium can be any available medium or data storage device accessible by the processor, including but not limited to magnetic memories (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc.), optical memories (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor memories (such as ROM, EPROM, EEPROM, non-volatile memories (NANDFLASH), solid-state drives (SSD)), etc.

[0544] Among them, the implementation embodiments of the key transmission methods on the network side device side, KMS side, first terminal side, second terminal side, or GMS side are all applicable to the embodiments of this processor-readable storage medium and can achieve the same technical effects.

[0545] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories and optical memories, etc.) containing computer-usable program code.

[0546] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0547] These processor-executable instructions can also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the processor-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0548] These processor-executable instructions may also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to generate a computer-implemented process, thereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one process or multiple processes and / or blocks Figure 1 one or more processes and / or blocks Figure 1 steps for implementing the functions specified in one block or multiple blocks.

[0549] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these changes and modifications.

Claims

1. A key transmission method for a temporary group, which is executed by a network-side device, characterized in that Including: When the first request sent by the first terminal meets the first preset condition, sending a reorganization request to the group management server GMS; wherein, the reorganization request carries the temporary group member identification information corresponding to the first request; Receiving the first response information sent by the GMS according to the reorganization request; wherein, the first response information carries a temporary group identifier; Generating a random number corresponding to the temporary group identifier, and the random number is used for the first terminal and the second terminal to determine the session key corresponding to the first request; wherein, the second terminal is the terminal corresponding to the temporary group member identification information.

2. The method according to claim 1, wherein Before sending the reorganization request to the group management server GMS, the method further includes: Sending a key material request to the key management server KMS; Receiving the second response information sent by the KMS according to the key material request; wherein, the second response information includes a temporary group key and a temporary group key identifier.

3. The method according to claim 1, wherein The first request carries the temporary group member identification information.

4. The method according to claim 1, wherein The first preset condition is one of the following: The first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call; The first request is a predefined dynamic reorganization request.

5. The method according to claim 4, wherein When the first request is a first group call request, after the method generates the random number corresponding to the temporary group identifier, the method further includes: Sending a second group call request to the second terminal; wherein, the second group call request carries the random number, the temporary group identifier, and the call type corresponding to the first group call request; Receiving the third response information sent by the second terminal according to the second group call request; wherein, the third response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request; Sending a fourth response information to the first terminal; wherein, the fourth response information is used to indicate that the temporary group call corresponding to the first request is successfully established; the fourth response information carries a temporary group identifier and a random number.

6. The method according to claim 4, characterized in that, When the first request is a predefined dynamic reorganization request, after the method generates the random number corresponding to the temporary group identifier, the method further includes: Sending the predefined dynamic reorganization request to the second terminal; Receiving the fifth response information sent by the second terminal according to the predefined dynamic reorganization request; Establishing a group association relationship between the second terminal and the temporary group identifier; Sending a sixth response information to the first terminal; wherein, the sixth response information carries a temporary group identifier and a random number.

7. The method according to claim 6, characterized in that, Also including: Receiving a third group call request sent by the first terminal; wherein, the third group call request carries the temporary group identifier; Sending a fourth group call request to the second terminal associated with the temporary group identifier; wherein, the fourth group call request carries the random number and the temporary group identifier; Receiving the seventh response information sent by the second terminal according to the predefined dynamic reorganization request; wherein, the seventh response information is used to indicate that the second terminal has joined the temporary group call corresponding to the first request; Send the eighth response message to the first terminal; wherein, the eighth response message carries a temporary group identifier, and the eighth response message is used to indicate the successful establishment of a temporary group call.

8. The method according to claim 2, characterized in that It further includes: When communicating with the GMS, encrypt the temporary group key and the temporary group key identifier using a preset key.

9. A key transmission method for a temporary group, which is executed by a first terminal, characterized in that It includes: Send a first request to the network-side device; wherein, the first request carries temporary group member identification information. Receive a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, and the group configuration request is sent according to a reorganization request sent by the network-side device, and the reorganization request is sent by the network-side device when the first request meets a first preset condition, and the reorganization request carries the temporary group member identification information, the temporary group key, and the temporary group key identifier corresponding to the first request. Obtain a random number; wherein, the random number corresponds to the temporary group identifier in the first response message sent by the GMS, and the first response message is sent by the GMS according to the reorganization request sent by the network-side device. Determine the session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

10. The method according to claim 9, wherein The first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call; or The first request is a predefined dynamic reorganization request.

11. The method according to claim 10, wherein When the first request is a first group call request, the obtaining of the random number includes: Receive a fourth response message sent by the network-side device; wherein, the fourth response message is used to indicate the successful establishment of a temporary group call corresponding to the first request; the fourth response message carries a temporary group identifier and a random number.

12. The method according to claim 10, wherein When the first request is a predefined dynamic reorganization request, the obtaining of the random number includes: Receive a sixth response message sent by the network-side device; wherein, the sixth response message carries a temporary group identifier and a random number.

13. The method according to claim 12, wherein After receiving the sixth response message sent by the network-side device, the method further includes: Send a third group call request to the network-side device; wherein, the third group call request carries the temporary group identifier. Receive an eighth response message sent by the network-side device; wherein, the eighth response message carries a temporary group identifier, and the eighth response message is used to indicate the successful establishment of a temporary group call.

14. The method according to claim 9, wherein After receiving the group configuration request sent by the GMS, the method further includes: Send a tenth response message to the GMS according to the group configuration request; wherein, the tenth response message is used to indicate that the first terminal has accepted the group configuration request.

15. A key transmission method for a temporary group, which is executed by a second terminal, characterized in that, It includes: Receive the group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to the reorganization request sent by the network-side device, and the reorganization request is sent by the network-side device when the first request meets the first preset condition, and the reorganization request carries the temporary group member identifier information, the temporary group key, and the temporary group key identifier corresponding to the first request; Obtain a random number; wherein, the random number corresponds to the temporary group identifier in the first response message sent by the GMS, and the first response message is sent by the GMS according to the reorganization request sent by the network-side device; Determine the session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

16. The method according to claim 15, wherein After receiving the group configuration request sent by the GMS, the method further includes: Send a ninth response message to the GMS according to the group configuration request; wherein, the ninth response message is used to indicate that the second terminal has accepted the group configuration request.

17. The method according to claim 15, wherein The obtaining of the random number includes: Receive the second group call request sent by the network-side device; wherein, the second group call request carries a random number, the temporary group identifier, and a call type.

18. The method according to claim 17, wherein Further includes: Send a third response message to the network-side device; wherein, the third response message is used to indicate that the second terminal has joined the temporary group call corresponding to the first request.

19. The method according to claim 15, characterized in that, Further includes: Receive the predefined dynamic reorganization request sent by the network-side device; Send a fifth response message to the network-side device according to the predefined dynamic reorganization request.

20. The method according to claim 15, characterized in that The obtaining of the random number includes: Receive the fourth group call request sent by the network-side device; wherein, the fourth group call request carries a random number and the temporary group identifier.

21. The method according to claim 20, characterized in that, Further includes: Send a seventh response message to the network-side device according to the fourth group call request; wherein, the seventh response message is used to indicate that the second terminal has joined the temporary group call corresponding to the first request.

22. A key transmission method for a temporary group, which is executed by the GMS, characterized in that, Includes: Receive the reorganization request sent by the network-side device; wherein, the reorganization request is sent by the network-side device when the first request meets the first preset condition, the first request is sent by the first terminal to the network-side device, and the reorganization request carries the temporary group member identifier information, the temporary group key, and the temporary group key identifier; Send a group configuration request to the first terminal and the second terminal corresponding to the temporary group member identifier information according to the reorganization request; wherein, the group configuration request carries the temporary group identifier, the temporary group key, and the temporary group key identifier; Receive the ninth response message sent by the second terminal according to the group configuration request, and receive the tenth response message sent by the first terminal according to the group configuration request; Send a first response message to the network-side device; wherein, the first response message carries the temporary group identifier.

23. The method according to claim 22, wherein Further includes: When communicating with the network-side device, encrypt the temporary group key and the temporary group key identifier using a preset key.

24. A network-side device, characterized in that, including a memory, a transceiver, and a processor: The memory is used for storing computer programs; the transceiver is used for transceiving data under the control of the processor; the processor is used for reading the computer programs in the memory and performing the following operations: When a first request sent by a first terminal meets a first preset condition, sending a reorganization request to a group management server GMS; wherein, the reorganization request carries temporary group member identification information corresponding to the first request; Receiving a first response message sent by the GMS according to the reorganization request; wherein, the first response message carries a temporary group identifier; Generating a random number corresponding to the temporary group identifier, where the random number is used for the first terminal and a second terminal to determine a session key corresponding to the first request; wherein, the second terminal is the terminal corresponding to the temporary group member identification information; 25. The network-side device according to claim 24, wherein The first preset condition is one of the following: The first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call; The first request is a predefined dynamic reorganization request.

26. A key transmission device for a temporary group, which is applied to a network-side device, is characterized in that, including: A first request unit, configured to send a reorganization request to a group management server GMS when a first request sent by a first terminal meets a first preset condition; wherein, the reorganization request carries temporary group member identification information corresponding to the first request; A first receiving unit, configured to receive a first response message sent by the GMS according to the reorganization request; wherein, the first response message carries a temporary group identifier; A first generating unit, configured to generate a random number corresponding to the temporary group identifier, where the random number is used for the first terminal and a second terminal to determine a session key corresponding to the first request; wherein, the second terminal is the terminal corresponding to the temporary group member identification information; 27. A terminal, the terminal being a first terminal, characterized in that, including a memory, a transceiver, and a processor: The memory is used for storing computer programs; the transceiver is used for transceiving data under the control of the processor; the processor is used for reading the computer programs in the memory and performing the following operations: Sending a first request to a network-side device; wherein, the first request carries temporary group member identification information; Receiving a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to a reorganization request sent by the network-side device, the reorganization request is sent by the network-side device when the first request meets a first preset condition, and the reorganization request carries temporary group member identification information, a temporary group key, and a temporary group key identifier corresponding to the first request; Obtaining a random number; wherein, the random number corresponds to the temporary group identifier in the first response message sent by the GMS, and the first response message is sent by the GMS according to the reorganization request sent by the network-side device; Determining a session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

28. The terminal according to claim 27, wherein The first request is a first group call request, and the call type corresponding to the first group call request is an ad-hoc mode temporary group call; or, The first request is a predefined dynamic reorganization request.

29. A key transmission device for a temporary group, applied to a first terminal, characterized in that, Including: A first call unit, configured to send a first request to a network-side device; wherein, the first request carries temporary group member identification information; A first reorganization unit, configured to receive a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to a reorganization request sent by the network-side device, the reorganization request is sent by the network-side device when the first request meets a first preset condition, and the reorganization request carries the temporary group member identification information, the temporary group key, and the temporary group key identifier corresponding to the first request; A first obtaining unit, configured to obtain a random number; wherein, the random number corresponds to the temporary group identifier in the first response information sent by the GMS, and the first response information is sent by the GMS according to the reorganization request sent by the network-side device; A first determining unit, configured to determine a session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

30. A terminal, the terminal being a second terminal, characterized in that, Including a memory, a transceiver, and a processor: The memory is configured to store a computer program; the transceiver is configured to send and receive data under the control of the processor; the processor is configured to read the computer program in the memory and perform the following operations: Receive a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to a reorganization request sent by the network-side device, the reorganization request is sent by the network-side device when the first request meets a first preset condition, and the reorganization request carries the temporary group member identification information, the temporary group key, and the temporary group key identifier corresponding to the first request; Obtain a random number; wherein, the random number corresponds to the temporary group identifier in the first response information sent by the GMS, and the first response information is sent by the GMS according to the reorganization request sent by the network-side device; Determine a session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

31. A key transmission device for a temporary group, applied to a second terminal, characterized in that Including: A second receiving unit, configured to receive a group configuration request sent by the GMS; wherein, the group configuration request carries a temporary group identifier, a temporary group key, and a temporary group key identifier, the group configuration request is sent according to a reorganization request sent by the network-side device, the reorganization request is sent by the network-side device when the first request meets a first preset condition, and the reorganization request carries the temporary group member identification information, the temporary group key, and the temporary group key identifier corresponding to the first request; A second obtaining unit, configured to obtain a random number; wherein, the random number corresponds to a temporary group identifier in the first response message sent by the GMS, and the first response message is sent by the GMS according to a recombination request sent by the network-side device; A second determining unit, configured to determine a session key corresponding to the first request according to the temporary group identifier, the temporary group key, the temporary group key identifier, and the random number.

32. A GMS, characterized in that, It includes a memory, a transceiver, and a processor: The memory is configured to store a computer program; the transceiver is configured to transmit and receive data under the control of the processor; the processor is configured to read the computer program in the memory and perform the following operations: Receive a recombination request sent by a network-side device; wherein, the recombination request is sent by the network-side device when a first request meets a first preset condition, the first request is sent by a first terminal to the network-side device, and the recombination request carries temporary group member identification information, a temporary group key, and a temporary group key identifier; According to the recombination request, send a group configuration request to the first terminal and the second terminal corresponding to the temporary group member identification information; wherein, the group configuration request carries a temporary group identifier, the temporary group key, and the temporary group key identifier; Receive a ninth response message sent by the second terminal according to the group configuration request, and receive a tenth response message sent by the first terminal according to the group configuration request; Send a first response message to the network-side device; wherein, the first response message carries a temporary group identifier.

33. A key transmission device for a temporary group, applied to GMS, is characterized in that It includes: A fourth receiving unit, configured to receive a recombination request sent by a network-side device; wherein, the recombination request is sent by the network-side device when a first request meets a first preset condition, the first request is sent by a first terminal to the network-side device, and the recombination request carries temporary group member identification information, a temporary group key, and a temporary group key identifier; A second sending unit, configured to send a group configuration request to the first terminal and the second terminal corresponding to the temporary group member identification information according to the recombination request; wherein, the group configuration request carries a temporary group identifier, the temporary group key, and the temporary group key identifier; A fifth receiving unit, configured to receive a ninth response message sent by the second terminal according to the group configuration request, and receive a tenth response message sent by the first terminal according to the group configuration request; A first response unit, configured to send a first response message to the network-side device; wherein, the first response message carries a temporary group identifier.

34. A processor-readable storage medium, characterized in that, The processor-readable storage medium stores a computer program, and the computer program is used to cause the processor to execute the method according to any one of claims 1 to 8; or, the computer program is used to cause the processor to execute the method according to any one of claims 9 to 14; or, the computer program is used to cause the processor to execute the method according to any one of claims 15 to 21; or, the computer program is used to cause the processor to execute the method according to any one of claims 22 to 23.

Citation Information

Patent Citations

  • Processing method, equipment and system of secure communication service

    CN104683304A

  • Temporary group call initiating method and device and storage medium

    CN111586593A

  • A method and system for end-to-end wireless encryption communication

    CN1671097A